DownPaper

S0186

Malware.View on attack.mitre.org

About this malware

DownPaper is a backdoor Trojan; its main functionality is to download and run second stage malware.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1012
Query Registry

DownPaper searches and reads the value of the Windows Update Registry Run key.

T1033
System Owner/User Discovery

DownPaper collects the victim username and sends it to the C2 server.

T1059.001
PowerShell

DownPaper uses PowerShell for execution.

T1059.003
Windows Command Shell

DownPaper uses the command line.

T1071.001
Web Protocols

DownPaper communicates to its C2 server over HTTP.

T1082
System Information Discovery

DownPaper collects the victim host name and serial number, and then sends the information to the C2 server.

T1547.001
Registry Run Keys / Startup Folder

DownPaper uses PowerShell to add a Registry Run key in order to establish persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ClearSky Charming Kitten Dec 2017 Open source
    ClearSky Cyber Security. (2017, December). Charming Kitten. Retrieved December 27, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.