ATT&CKSoftwareMatryoshka

Matryoshka

S0167

Malware.View on attack.mitre.org

About this malware

Matryoshka is a malware framework used by CopyKittens that consists of a dropper, loader, and RAT. It has multiple versions; v1 was seen in the wild from July 2016 until January 2017. v2 has fewer commands and other minor differences.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1027
Obfuscated Files or Information

Matryoshka obfuscates API function names using a substitute cipher combined with Base64 encoding.

T1053.005
Scheduled Task

Matryoshka can establish persistence by adding a Scheduled Task named "Microsoft Boost Kernel Optimization".

T1055.001
Dynamic-link Library Injection

Matryoshka uses reflective DLL injection to inject the malicious library and execute the RAT.

T1056.001
Keylogging

Matryoshka is capable of keylogging.

T1059
Command and Scripting Interpreter

Matryoshka is capable of providing Meterpreter shell access.

T1071.004
DNS

Matryoshka uses DNS for C2.

T1113
Screen Capture

Matryoshka is capable of performing screen captures.

T1218.011
Rundll32

Matryoshka uses rundll32.exe in a Registry Run key value for execution as part of its persistence mechanism.

T1547.001
Registry Run Keys / Startup Folder

Matryoshka can establish persistence by adding Registry Run keys.

T1555
Credentials from Password Stores

Matryoshka is capable of stealing Outlook passwords.

Groups that use it1

Campaigns0

None recorded.

References2

  1. ClearSky Wilted Tulip July 2017 Open source
    ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.
  2. CopyKittens Nov 2015 Open source
    Minerva Labs LTD and ClearSky Cyber Security. (2015, November 23). CopyKittens Attack Group. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.