ATT&CKSoftwareADVSTORESHELL

ADVSTORESHELL

S0045

Malware.View on attack.mitre.org

About this malware

ADVSTORESHELL is a spying backdoor that has been used by APT28 from at least 2012 to 2016. It is generally used for long-term espionage and is deployed on targets deemed interesting after a reconnaissance phase.

Techniques used23

Procedure examples23

TechniqueProcedure example
T1012
Query Registry

ADVSTORESHELL can enumerate registry keys.

T1027
Obfuscated Files or Information

Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory.

T1029
Scheduled Transfer

ADVSTORESHELL collects, compresses, encrypts, and exfiltrates data to the C2 server every 10 minutes.

T1041
Exfiltration Over C2 Channel

ADVSTORESHELL exfiltrates data over the same channel used for C2.

T1056.001
Keylogging

ADVSTORESHELL can perform keylogging.

T1057
Process Discovery

ADVSTORESHELL can list running processes.

T1059.003
Windows Command Shell

ADVSTORESHELL can create a remote shell and run a given command.

T1070.004
File Deletion

ADVSTORESHELL can delete files and directories.

T1071.001
Web Protocols

ADVSTORESHELL connects to port 80 of a C2 server using Wininet API. Data is exchanged via HTTP POSTs.

T1074.001
Local Data Staging

ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory.

T1082
System Information Discovery

ADVSTORESHELL can run Systeminfo to gather information about the victim.

T1083
File and Directory Discovery

ADVSTORESHELL can list files and directories.

T1106
Native API

ADVSTORESHELL is capable of starting a process using CreateProcess.

T1112
Modify Registry

ADVSTORESHELL is capable of setting and deleting Registry values.

T1120
Peripheral Device Discovery

ADVSTORESHELL can list connected devices.

View all 23 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. ESET Sednit Part 2 Open source
    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.
  2. Kaspersky Sofacy Open source
    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.