Prikormka

S0113

Malware.View on attack.mitre.org

About this malware

Prikormka is a malware family used in a campaign known as Operation Groundbait. It has predominantly been observed in Ukraine and was used as early as 2008.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1016
System Network Configuration Discovery

A module in Prikormka collects information from the victim about its IP addresses and MAC addresses.

T1025
Data from Removable Media

Prikormka contains a module that collects documents with certain extensions from removable media or fixed drives connected via USB.

T1027.013
Encrypted/Encoded File

Some resources in Prikormka are encrypted with a simple XOR operation or encoded with Base64.

T1033
System Owner/User Discovery

A module in Prikormka collects information from the victim about the current user name.

T1056.001
Keylogging

Prikormka contains a keylogger module that collects keystrokes and the titles of foreground windows.

T1070.004
File Deletion

After encrypting its own log files, the log encryption module in Prikormka deletes the original, unencrypted files from the host.

T1074.001
Local Data Staging

Prikormka creates a directory, %USERPROFILE%\AppData\Local\SKC\, which is used to store collected log files.

T1082
System Information Discovery

A module in Prikormka collects information from the victim about Windows OS version, computer name, battery info, and physical memory.

T1083
File and Directory Discovery

A module in Prikormka collects information about the paths, size, and creation time of files with specific file extensions, but not the actual content of the file.

T1113
Screen Capture

Prikormka contains a module that captures screenshots of the victim's desktop.

T1120
Peripheral Device Discovery

A module in Prikormka collects information on available printers and disk drives.

T1132.001
Standard Encoding

Prikormka encodes C2 traffic with Base64.

T1218.011
Rundll32

Prikormka uses rundll32.exe to load its DLL.

T1518.001
Security Software Discovery

A module in Prikormka collects information from the victim about installed anti-virus software.

T1547.001
Registry Run Keys / Startup Folder

Prikormka adds itself to a Registry Run key with the name guidVGA or guidVSA.

View all 20 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. ESET Operation Groundbait Open source
    Cherepanov, A.. (2016, May 17). Operation Groundbait: Analysis of a surveillance toolkit. Retrieved May 18, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.