Sykipot

S0018

Malware.View on attack.mitre.org

About this malware

Sykipot is malware that has been used in spearphishing campaigns since approximately 2007 against victims primarily in the US. One variant of Sykipot hijacks smart cards on victims. The group using this malware has also been referred to as Sykipot.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1007
System Service Discovery

Sykipot may use net start to display running services.

T1016
System Network Configuration Discovery

Sykipot may use ipconfig /all to gather system network configuration details.

T1018
Remote System Discovery

Sykipot may use net view /domain to display hostnames of available systems on a network.

T1049
System Network Connections Discovery

Sykipot may use netstat -ano to display active network connections.

T1055.001
Dynamic-link Library Injection

Sykipot injects itself into running instances of outlook.exe, iexplore.exe, or firefox.exe.

T1056.001
Keylogging

Sykipot contains keylogging functionality to steal passwords.

T1057
Process Discovery

Sykipot may gather a list of running processes by running tasklist /v.

T1087.002
Domain Account

Sykipot may use net group "domain admins" /domain to display accounts in the "domain admins" permissions group and net localgroup "administrators" to list local system administrator group membership.

T1111
Multi-Factor Authentication Interception

Sykipot is known to contain functionality that enables targeting of smart card technologies to proxy authentication for connections to restricted network resources using detected hardware tokens.

T1547.001
Registry Run Keys / Startup Folder

Sykipot has been known to establish persistence by adding programs to the Run Registry key.

T1573.002
Asymmetric Cryptography

Sykipot uses SSL for encrypting C2 communications.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Alienvault Sykipot DOD Smart Cards Open source
    Blasco, J. (2012, January 12). Sykipot variant hijacks DOD and Windows smart cards. Retrieved January 10, 2016.
  2. Blasco 2013 Open source
    Blasco, J. (2013, March 21). New Sykipot developments [Blog]. Retrieved November 12, 2014.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.