OLDBAIT

S0138

Malware.View on attack.mitre.org

About this malware

OLDBAIT is a credential harvester used by APT28.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027
Obfuscated Files or Information

OLDBAIT obfuscates internal strings and unpacks them at startup.

T1036.005
Match Legitimate Resource Name or Location

OLDBAIT installs itself in %ALLUSERPROFILE%\\Application Data\Microsoft\MediaPlayer\updatewindws.exe; the directory name is missing a space and the file name is missing the letter "o."

T1071.001
Web Protocols

OLDBAIT can use HTTP for C2.

T1071.003
Mail Protocols

OLDBAIT can use SMTP for C2.

T1555
Credentials from Password Stores

OLDBAIT collects credentials from several email clients.

T1555.003
Credentials from Web Browsers

OLDBAIT collects credentials from Internet Explorer, Mozilla Firefox, and Eudora.

Groups that use it1

Campaigns0

None recorded.

References2

  1. FireEye APT28 Open source
    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.
  2. FireEye APT28 January 2017 Open source
    FireEye iSIGHT Intelligence. (2017, January 11). APT28: At the Center of the Storm. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.