Agent.btz

S0092

Malware.View on attack.mitre.org

About this malware

Agent.btz is a worm that primarily spreads itself via removable devices such as USB drives. It reportedly infected U.S. military networks in 2008.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1016
System Network Configuration Discovery

Agent.btz collects the network adapter’s IP and MAC address as well as IP addresses of the network adapter’s default gateway, primary/secondary WINS, DHCP, and DNS servers, and saves them into a log file.

T1033
System Owner/User Discovery

Agent.btz obtains the victim username and saves it to a file.

T1052.001
Exfiltration over USB

Agent.btz creates a file named thumb.dd on all USB flash drives connected to the victim. This file contains information about the infected system and activity logs.

T1091
Replication Through Removable Media

Agent.btz drops itself onto removable media devices and creates an autorun.inf file with an instruction to run that file. When the device is inserted into another system, it opens autorun.inf and loads the malware.

T1105
Ingress Tool Transfer

Agent.btz attempts to download an encrypted binary from a specified domain.

T1560.003
Archive via Custom Method

Agent.btz saves system information into an XML file that is then XOR-encoded.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Securelist Agent.btz Open source
    Gostev, A.. (2014, March 12). Agent.btz: a Source of Inspiration?. Retrieved April 8, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.