Malware.View on attack.mitre.org
BBSRAT is malware with remote access tool functionality that has been used in targeted compromises.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
BBSRAT can query service configuration information. |
| T1055.012 Process Hollowing |
BBSRAT has been seen loaded into msiexec.exe through process hollowing to hide its execution. |
| T1057 Process Discovery |
BBSRAT can list running processes. |
| T1070.004 File Deletion |
BBSRAT can delete files and directories. |
| T1071.001 Web Protocols |
BBSRAT uses GET and POST requests over HTTP or HTTPS for command and control to obtain commands and send ZLIB compressed data back to the C2 server. |
| T1083 File and Directory Discovery |
BBSRAT can list file and directory information. |
| T1140 Deobfuscate/Decode Files or Information |
BBSRAT uses Expand to decompress a CAB file into executable content. |
| T1543.003 Windows Service |
BBSRAT can modify service configurations. |
| T1546.015 Component Object Model Hijacking |
BBSRAT has been seen persisting via COM hijacking through replacement of the COM object for MruPidlList |
| T1547.001 Registry Run Keys / Startup Folder |
BBSRAT has been loaded through DLL side-loading of a legitimate Citrix executable that is set to persist through the Registry Run key location |
| T1560.002 Archive via Library |
BBSRAT can compress data with ZLIB prior to sending it back to the C2 server. |
| T1569.002 Service Execution |
BBSRAT can start, stop, or delete services. |
| T1573.001 Symmetric Cryptography |
BBSRAT uses a custom encryption algorithm on data sent back to the C2 server over HTTP. |
| T1574.001 DLL |
DLL side-loading has been used to execute BBSRAT through a legitimate Citrix executable, ssonsvr.exe. The Citrix executable was dropped along with BBSRAT by the dropper. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.