Elise

S0081

Malware.View on attack.mitre.org

About this malware

Elise is a custom backdoor Trojan that appears to be used exclusively by Lotus Blossom. It is part of a larger group of tools referred to as LStudio, ST Group, and APT0LSTU.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1007
System Service Discovery

Elise executes net start after initial communication is made to the remote server.

T1016
System Network Configuration Discovery

Elise executes ipconfig /all after initial communication is made to the remote server.

T1027.013
Encrypted/Encoded File

Elise encrypts several of its files, including configuration files.

T1036.005
Match Legitimate Resource Name or Location

If installing itself as a service fails, Elise instead writes itself as a file named svchost.exe saved in %APPDATA%\Microsoft\Network.

T1055.001
Dynamic-link Library Injection

Elise injects DLL files into iexplore.exe.

T1057
Process Discovery

Elise enumerates processes via the tasklist command.

T1070.004
File Deletion

Elise is capable of launching a remote shell on the host to delete itself.

T1070.006
Timestomp

Elise performs timestomping of a CAB file it creates.

T1071.001
Web Protocols

Elise communicates over HTTP or HTTPS for C2.

T1074.001
Local Data Staging

Elise creates a file in AppData\Local\Microsoft\Windows\Explorer and stores all harvested data in that file.

T1082
System Information Discovery

Elise executes systeminfo after initial communication is made to the remote server.

T1083
File and Directory Discovery

A variant of Elise executes dir C:\progra~1 when initially run.

T1087.001
Local Account

Elise executes net user after initial communication is made to the remote server.

T1105
Ingress Tool Transfer

Elise can download additional files from the C2 server for execution.

T1132.001
Standard Encoding

Elise exfiltrates data using cookie values that are Base64-encoded.

View all 19 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Accenture Dragonfish Jan 2018 Open source
    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.
  2. Lotus Blossom Jun 2015 Open source
    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.