Crimson

S0115

Malware.View on attack.mitre.org

About this malware

Crimson is a remote access Trojan that has been used by Transparent Tribe since at least 2016.

Techniques used30

Procedure examples30

TechniqueProcedure example
T1005
Data from Local System

Crimson can collect information from a compromised host.

T1012
Query Registry

Crimson can check the Registry for the presence of HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\last_edate to determine how long it has been installed on a host.

T1016
System Network Configuration Discovery

Crimson contains a command to collect the victim MAC address and LAN IP.

T1025
Data from Removable Media

Crimson contains a module to collect data from removable drives.

T1033
System Owner/User Discovery

Crimson can identify the user on a targeted system.

T1041
Exfiltration Over C2 Channel

Crimson can exfiltrate stolen information over its C2.

T1056.001
Keylogging

Crimson can use a module to perform keylogging on compromised hosts.

T1057
Process Discovery

Crimson contains a command to list processes.

T1059.003
Windows Command Shell

Crimson has the ability to execute commands with the COMSPEC environment variable.

T1070.004
File Deletion

Crimson has the ability to delete files from a compromised host.

T1071.001
Web Protocols

Crimson can use a HTTP GET request to download its final payload.

T1082
System Information Discovery

Crimson contains a command to collect the victim PC name and operating system.

T1083
File and Directory Discovery

Crimson contains commands to list files and directories, as well as search for files matching certain extensions from a defined list.

T1091
Replication Through Removable Media

Crimson can spread across systems by infecting removable media.

T1095
Non-Application Layer Protocol

Crimson uses a custom TCP protocol for C2.

View all 30 procedure examples

Groups that use it1

Campaigns1

References2

  1. Kaspersky Transparent Tribe August 2020 Open source
    Dedola, G. (2020, August 20). Transparent Tribe: Evolution analysis, part 1. Retrieved September 2, 2021.
  2. Proofpoint Operation Transparent Tribe March 2016 Open source
    Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.