Regin

S0019

Malware.View on attack.mitre.org

About this malware

Regin is a malware platform that has targeted victims in a range of industries, including telecom, government, and financial institutions. Some Regin timestamps date back to 2003.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1021.002
SMB/Windows Admin Shares

The Regin malware platform can use Windows admin shares to move laterally.

T1036.001
Invalid Code Signature

Regin stage 1 modules for 64-bit systems have been found to be signed with fake certificates masquerading as originating from Microsoft Corporation and Broadcom Corporation.

T1040
Network Sniffing

Regin appears to have functionality to sniff for credentials passed over HTTP, SMTP, and SMB.

T1056.001
Keylogging

Regin contains a keylogger.

T1071.001
Web Protocols

The Regin malware platform supports many standard protocols, including HTTP and HTTPS.

T1071.002
File Transfer Protocols

The Regin malware platform supports many standard protocols, including SMB.

T1090.002
External Proxy

Regin leveraged several compromised universities as proxies to obscure its origin.

T1095
Non-Application Layer Protocol

The Regin malware platform can use ICMP to communicate between infected computers.

T1112
Modify Registry

Regin appears to have functionality to modify remote Registry information.

T1564.004
NTFS File Attributes

The Regin malware platform uses Extended Attributes to store encrypted executables.

T1564.005
Hidden File System

Regin has used a hidden file system to store some of its components.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Kaspersky Regin Open source
    Kaspersky Lab's Global Research and Analysis Team. (2014, November 24). THE REGIN PLATFORM NATION-STATE OWNAGE OF GSM NETWORKS. Retrieved December 1, 2014.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.