NanHaiShu

S0228

Malware.View on attack.mitre.org

About this malware

NanHaiShu is a remote access tool and JScript backdoor used by Leviathan. NanHaiShu has been used to target government and private-sector organizations that have relations to the South China Sea dispute.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1016
System Network Configuration Discovery

NanHaiShu can gather information about the victim proxy server.

T1027.013
Encrypted/Encoded File

NanHaiShu encodes files in Base64.

T1033
System Owner/User Discovery

NanHaiShu collects the username from the victim.

T1059.005
Visual Basic

NanHaiShu executes additional VBScript code on the victim's machine.

T1059.007
JavaScript

NanHaiShu executes additional Jscript code on the victim's machine.

T1070.004
File Deletion

NanHaiShu launches a script to delete their original decoy file to cover tracks.

T1071.004
DNS

NanHaiShu uses DNS for the C2 communications.

T1082
System Information Discovery

NanHaiShu can gather the victim computer name and serial number.

T1105
Ingress Tool Transfer

NanHaiShu can download additional files from URLs.

T1218.005
Mshta

NanHaiShu uses mshta.exe to load its program and files.

T1547.001
Registry Run Keys / Startup Folder

NanHaiShu modifies the %regrun% Registry to point itself to an autostart mechanism.

T1685
Disable or Modify Tools

NanHaiShu can change Internet Explorer settings to reduce warnings about malware activity.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Proofpoint Leviathan Oct 2017 Open source
    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.
  2. fsecure NanHaiShu July 2016 Open source
    F-Secure Labs. (2016, July). NANHAISHU RATing the South China Sea. Retrieved July 6, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.