MoonWind

S0149

Malware.View on attack.mitre.org

About this malware

MoonWind is a remote access tool (RAT) that was used in 2016 to target organizations in Thailand.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1016
System Network Configuration Discovery

MoonWind obtains the victim IP address.

T1033
System Owner/User Discovery

MoonWind obtains the victim username.

T1056.001
Keylogging

MoonWind has a keylogger.

T1057
Process Discovery

MoonWind has a command to return a list of running processes.

T1059.003
Windows Command Shell

MoonWind can execute commands via an interactive command shell. MoonWind uses batch scripts for various purposes, including to restart and uninstall itself.

T1070.004
File Deletion

MoonWind can delete itself or specified files.

T1074.001
Local Data Staging

MoonWind saves information from its keylogging routine as a .zip file in the present working directory.

T1082
System Information Discovery

MoonWind can obtain the victim hostname, Windows version, RAM amount, and screen resolution.

T1083
File and Directory Discovery

MoonWind has a command to return a directory listing for a specified directory.

T1095
Non-Application Layer Protocol

MoonWind completes network communication via raw sockets.

T1120
Peripheral Device Discovery

MoonWind obtains the number of removable drives from the victim.

T1124
System Time Discovery

MoonWind obtains the victim's current time.

T1543.003
Windows Service

MoonWind installs itself as a new service with automatic startup to establish persistence. The service checks every 60 seconds to determine if the malware is running; if not, it will spawn a new instance.

T1571
Non-Standard Port

MoonWind communicates over ports 80, 443, 53, and 8080 via raw sockets instead of the protocols usually associated with the ports.

T1573.001
Symmetric Cryptography

MoonWind encrypts C2 traffic using RC4 with a static key.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Palo Alto MoonWind March 2017 Open source
    Miller-Osborn, J. and Grunzweig, J.. (2017, March 30). Trochilus and New MoonWind RATs Used In Attack Against Thai Organizations. Retrieved March 30, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.