Helminth

S0170

Malware.View on attack.mitre.org

About this malware

Helminth is a backdoor that has at least two variants - one written in VBScript and PowerShell that is delivered via a macros in Excel spreadsheets, and one that is a standalone Windows executable.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

The Helminth config file is encrypted with RC4.

T1030
Data Transfer Size Limits

Helminth splits data into chunks up to 23 bytes and sends the data in DNS queries to its C2 server.

T1053.005
Scheduled Task

Helminth has used a scheduled task for persistence.

T1056.001
Keylogging

The executable version of Helminth has a module to log keystrokes.

T1057
Process Discovery

Helminth has used Tasklist to get information on processes.

T1059.001
PowerShell

One version of Helminth uses a PowerShell script.

T1059.003
Windows Command Shell

Helminth can provide a remote shell. One version of Helminth uses batch scripting.

T1059.005
Visual Basic

One version of Helminth consists of VBScript scripts.

T1069.001
Local Groups

Helminth has checked the local administrators group.

T1069.002
Domain Groups

Helminth has checked for the domain admin group and Exchange Trusted Subsystem groups using the commands net group Exchange Trusted Subsystem /domain and net group domain admins /domain.

T1071.001
Web Protocols

Helminth can use HTTP for C2.

T1071.004
DNS

Helminth can use DNS for C2.

T1074.001
Local Data Staging

Helminth creates folders to store output from batch scripts prior to sending the information to its C2 server.

T1105
Ingress Tool Transfer

Helminth can download additional files.

T1115
Clipboard Data

The executable version of Helminth has a module to log clipboard contents.

View all 21 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Palo Alto OilRig May 2016 Open source
    Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.