Malware.View on attack.mitre.org
Backdoor.Oldrea is a modular backdoor that used by Dragonfly against energy companies since at least 2013. Backdoor.Oldrea was distributed via supply chain compromise, and included specialized modules to enumerate and map ICS-specific systems, processes, and protocols.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Backdoor.Oldrea collects information about the Internet adapter configuration. |
| T1018 Remote System Discovery |
Backdoor.Oldrea can enumerate and map ICS-specific systems in victim environments. |
| T1033 System Owner/User Discovery |
Backdoor.Oldrea collects the current username from the victim. |
| T1046 Network Service Discovery |
Backdoor.Oldrea can use a network scanning module to identify ICS-related ports. |
| T1055 Process Injection |
Backdoor.Oldrea injects itself into explorer.exe. |
| T1057 Process Discovery |
Backdoor.Oldrea collects information about running processes. |
| T1070.004 File Deletion |
Backdoor.Oldrea contains a cleanup module that removes traces of itself from the victim. |
| T1082 System Information Discovery |
Backdoor.Oldrea collects information about the OS and computer name. |
| T1083 File and Directory Discovery |
Backdoor.Oldrea collects information about available drives, default browser, desktop file list, My Documents, Internet history, program files, and root of available drives. It also searches for ICS-related software files. |
| T1087.003 Email Account |
Backdoor.Oldrea collects address book information from Outlook. |
| T1105 Ingress Tool Transfer |
Backdoor.Oldrea can download additional modules from C2. |
| T1132.001 Standard Encoding |
Some Backdoor.Oldrea samples use standard Base64 + bzip2, and some use standard Base64 + reverse XOR + RSA-2048 to decrypt data received from C2 servers. |
| T1218.011 Rundll32 |
Backdoor.Oldrea can use rundll32 for execution on compromised hosts. |
| T1547.001 Registry Run Keys / Startup Folder |
Backdoor.Oldrea adds Registry Run keys to achieve persistence. |
| T1555.003 Credentials from Web Browsers |
Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.