Emissary

S0082

Malware.View on attack.mitre.org

About this malware

Emissary is a Trojan that has been used by Lotus Blossom. It shares code with Elise, with both Trojans being part of a malware group referred to as LStudio.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1007
System Service Discovery

Emissary has the capability to execute the command net start to interact with services.

T1016
System Network Configuration Discovery

Emissary has the capability to execute the command ipconfig /all.

T1027.001
Binary Padding

A variant of Emissary appends junk data to the end of its DLL file to create a large file that may exceed the maximum size that anti-virus programs can scan.

T1027.013
Encrypted/Encoded File

Variants of Emissary encrypt payloads using various XOR ciphers, as well as a custom algorithm that uses the "srand" and "rand" functions.

T1055.001
Dynamic-link Library Injection

Emissary injects its DLL file into a newly spawned Internet Explorer process.

T1059.003
Windows Command Shell

Emissary has the capability to create a remote shell and execute specified commands.

T1069.001
Local Groups

Emissary has the capability to execute the command net localgroup administrators.

T1071.001
Web Protocols

Emissary uses HTTP or HTTPS for C2.

T1082
System Information Discovery

Emissary has the capability to execute ver and systeminfo commands.

T1105
Ingress Tool Transfer

Emissary has the capability to download files from the C2 server.

T1218.011
Rundll32

Variants of Emissary have used rundll32.exe in Registry values added to establish persistence.

T1543.003
Windows Service

Emissary is capable of configuring itself as a service.

T1547.001
Registry Run Keys / Startup Folder

Variants of Emissary have added Run Registry keys to establish persistence.

T1573.001
Symmetric Cryptography

The C2 server response to a beacon sent by a variant of Emissary contains a 36-character GUID value that is used as an encryption key for subsequent network communications. Some variants of Emissary use various XOR operations to encrypt C2 data.

T1615
Group Policy Discovery

Emissary has the capability to execute gpresult.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Lotus Blossom Dec 2015 Open source
    Falcone, R. and Miller-Osborn, J.. (2015, December 18). Attack on French Diplomat Linked to Operation Lotus Blossom. Retrieved February 15, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.