BBSRAT

S0127

Malware.View on attack.mitre.org

About this malware

BBSRAT is malware with remote access tool functionality that has been used in targeted compromises.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1007
System Service Discovery

BBSRAT can query service configuration information.

T1055.012
Process Hollowing

BBSRAT has been seen loaded into msiexec.exe through process hollowing to hide its execution.

T1057
Process Discovery

BBSRAT can list running processes.

T1070.004
File Deletion

BBSRAT can delete files and directories.

T1071.001
Web Protocols

BBSRAT uses GET and POST requests over HTTP or HTTPS for command and control to obtain commands and send ZLIB compressed data back to the C2 server.

T1083
File and Directory Discovery

BBSRAT can list file and directory information.

T1140
Deobfuscate/Decode Files or Information

BBSRAT uses Expand to decompress a CAB file into executable content.

T1543.003
Windows Service

BBSRAT can modify service configurations.

T1546.015
Component Object Model Hijacking

BBSRAT has been seen persisting via COM hijacking through replacement of the COM object for MruPidlList {42aedc87-2188-41fd-b9a3-0c966feabec1} or Microsoft WBEM New Event Subsystem {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} depending on the system's CPU architecture.

T1547.001
Registry Run Keys / Startup Folder

BBSRAT has been loaded through DLL side-loading of a legitimate Citrix executable that is set to persist through the Registry Run key location HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ssonsvr.exe.

T1560.002
Archive via Library

BBSRAT can compress data with ZLIB prior to sending it back to the C2 server.

T1569.002
Service Execution

BBSRAT can start, stop, or delete services.

T1573.001
Symmetric Cryptography

BBSRAT uses a custom encryption algorithm on data sent back to the C2 server over HTTP.

T1574.001
DLL

DLL side-loading has been used to execute BBSRAT through a legitimate Citrix executable, ssonsvr.exe. The Citrix executable was dropped along with BBSRAT by the dropper.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Palo Alto Networks BBSRAT Open source
    Lee, B. Grunzweig, J. (2015, December 22). BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger. Retrieved August 19, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.