DOGCALL

S0213

Malware.View on attack.mitre.org

About this malware

DOGCALL is a backdoor used by APT37 that has been used to target South Korean government and military organizations in 2017. It is typically dropped using a Hangul Word Processor (HWP) exploit.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

DOGCALL is encrypted using single-byte XOR.

T1056.001
Keylogging

DOGCALL is capable of logging keystrokes.

T1102.002
Bidirectional Communication

DOGCALL is capable of leveraging cloud storage APIs such as Cloud, Box, Dropbox, and Yandex for C2.

T1105
Ingress Tool Transfer

DOGCALL can download and execute additional payloads.

T1113
Screen Capture

DOGCALL is capable of capturing screenshots of the victim's machine.

T1123
Audio Capture

DOGCALL can capture microphone data from the victim's machine.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT37 Feb 2018 Open source
    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.