RedLeaves

S0153

Malware.View on attack.mitre.org

About this malware

RedLeaves is a malware family used by menuPass. The code overlaps with PlugX and may be based upon the open source tool Trochilus.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1016
System Network Configuration Discovery

RedLeaves can obtain information about network parameters.

T1027.013
Encrypted/Encoded File

A RedLeaves configuration file is encrypted with a simple XOR key, 0x53.

T1033
System Owner/User Discovery

RedLeaves can obtain information about the logged on user both locally and for Remote Desktop sessions.

T1049
System Network Connections Discovery

RedLeaves can enumerate drives and Remote Desktop sessions.

T1059.003
Windows Command Shell

RedLeaves can receive and execute commands with cmd.exe. It can also provide a reverse shell.

T1070.004
File Deletion

RedLeaves can delete specified files.

T1071.001
Web Protocols

RedLeaves can communicate to its C2 over HTTP and HTTPS if directed.

T1082
System Information Discovery

RedLeaves can gather extended system information including the hostname, OS version number, platform, memory information, time elapsed since system startup, and CPU information.

T1083
File and Directory Discovery

RedLeaves can enumerate and search for files and directories.

T1105
Ingress Tool Transfer

RedLeaves is capable of downloading a file from a specified URL.

T1113
Screen Capture

RedLeaves can capture screenshots.

T1547.001
Registry Run Keys / Startup Folder

RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence. If this fails, it attempts to add Registry Run keys.

T1547.009
Shortcut Modification

RedLeaves attempts to add a shortcut file in the Startup folder to achieve persistence.

T1555.003
Credentials from Web Browsers

RedLeaves can gather browser usernames and passwords.

T1571
Non-Standard Port

RedLeaves can use HTTP over non-standard ports, such as 995, for C2.

View all 17 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. FireEye APT10 April 2017 Open source
    FireEye iSIGHT Intelligence. (2017, April 6). APT10 (MenuPass Group): New Tools, Global Campaign Latest Manifestation of Longstanding Threat. Retrieved June 29, 2017.
  2. PWC Cloud Hopper Technical Annex April 2017 Open source
    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.