FakeM

S0076

Malware.View on attack.mitre.org

About this malware

FakeM is a shellcode-based Windows backdoor that has been used by Scarlet Mimic.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

FakeM C2 traffic attempts to evade detection by resembling data generated by legitimate messenger applications, such as MSN and Yahoo! messengers. Additionally, some variants of FakeM use modified SSL code for communications back to C2 servers, making SSL decryption ineffective.

T1056.001
Keylogging

FakeM contains a keylogger module.

T1095
Non-Application Layer Protocol

Some variants of FakeM use SSL to communicate with C2 servers.

T1573.001
Symmetric Cryptography

The original variant of FakeM encrypts C2 traffic using a custom encryption cipher that uses an XOR key of “YHCRA” and bit rotation between each XOR operation. Some variants of FakeM use RC4 to encrypt C2 traffic.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Scarlet Mimic Jan 2016 Open source
    Falcone, R. and Miller-Osborn, J.. (2016, January 24). Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists. Retrieved February 10, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.