CORALDECK

S0212

Malware.View on attack.mitre.org

About this malware

CORALDECK is an exfiltration tool used by APT37.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

CORALDECK has exfiltrated data in HTTP POST headers.

T1083
File and Directory Discovery

CORALDECK searches for specified files.

T1560.001
Archive via Utility

CORALDECK has created password-protected RAR, WinImage, and zip archives to be exfiltrated.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT37 Feb 2018 Open source
    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.