Daserf

S0187

Malware.View on attack.mitre.org

About this malware

Daserf is a backdoor that has been used to spy on and steal from Japanese, South Korean, Russian, Singaporean, and Chinese victims. Researchers have identified versions written in both Visual C and Delphi.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1001.002
Steganography

Daserf can use steganography to hide malicious code downloaded to the victim.

T1003.001
LSASS Memory

Daserf leverages Mimikatz and Windows Credential Editor to steal credentials.

T1027
Obfuscated Files or Information

Daserf uses encrypted Windows APIs and also encrypts data using the alternative base64+RC4 or the Caesar cipher.

T1027.002
Software Packing

A version of Daserf uses the MPRESS packer.

T1027.005
Indicator Removal from Tools

Analysis of Daserf has shown that it regularly undergoes technical improvements to evade anti-virus detection.

T1036.005
Match Legitimate Resource Name or Location

Daserf uses file and folder names related to legitimate programs in order to blend in, such as HP, Intel, Adobe, and perflogs.

T1056.001
Keylogging

Daserf can log keystrokes.

T1059.003
Windows Command Shell

Daserf can execute shell commands.

T1071.001
Web Protocols

Daserf uses HTTP for C2.

T1105
Ingress Tool Transfer

Daserf can download remote files.

T1113
Screen Capture

Daserf can take screenshots.

T1132.001
Standard Encoding

Daserf uses custom base64 encoding to obfuscate HTTP traffic.

T1553.002
Code Signing

Some Daserf samples were signed with a stolen digital certificate.

T1560
Archive Collected Data

Daserf hides collected data in password-protected .rar archives.

T1560.001
Archive via Utility

Daserf hides collected data in password-protected .rar archives.

View all 16 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Secureworks BRONZE BUTLER Oct 2017 Open source
    Counter Threat Unit Research Team. (2017, October 12). BRONZE BUTLER Targets Japanese Enterprises. Retrieved January 4, 2018.
  2. Trend Micro Daserf Nov 2017 Open source
    Chen, J. and Hsieh, M. (2017, November 7). REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography. Retrieved December 27, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.