Malware.View on attack.mitre.org
CHOPSTICK is a malware family of modular backdoors used by APT28. It has been used since at least 2012 and is usually dropped on victims as second-stage malware, though it has been used as first-stage malware in several cases. It has both Windows and Linux variants. It is tracked separately from the X-Agent for Android.
| Technique | Procedure example |
|---|---|
| T1008 Fallback Channels |
CHOPSTICK can switch to a new C2 channel if the current one is broken. |
| T1012 Query Registry |
CHOPSTICK provides access to the Windows Registry, which can be used to gather information. |
| T1027.011 Fileless Storage |
CHOPSTICK may store RC4 encrypted configuration information in the Windows Registry. |
| T1056.001 Keylogging |
CHOPSTICK is capable of performing keylogging. |
| T1059 Command and Scripting Interpreter |
CHOPSTICK is capable of performing remote command execution. |
| T1071.001 Web Protocols |
Various implementations of CHOPSTICK communicate with C2 over HTTP. |
| T1071.003 Mail Protocols |
Various implementations of CHOPSTICK communicate with C2 over SMTP and POP3. |
| T1083 File and Directory Discovery |
An older version of CHOPSTICK has a module that monitors all mounted volumes for files with the extensions .doc, .docx, .pgp, .gpg, .m2f, or .m2o. |
| T1090.001 Internal Proxy |
CHOPSTICK used a proxy server between victims and the C2 server. |
| T1091 Replication Through Removable Media |
Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic. |
| T1092 Communication Through Removable Media |
Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines, using files written to USB sticks to transfer data and command traffic. |
| T1105 Ingress Tool Transfer |
CHOPSTICK is capable of performing remote file transmission. |
| T1112 Modify Registry |
CHOPSTICK may modify Registry keys to store RC4 encrypted configuration information. |
| T1113 Screen Capture |
CHOPSTICK has the capability to capture screenshots. |
| T1497 Virtualization/Sandbox Evasion |
CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.