BADCALL

S0245

Malware.View on attack.mitre.org

About this malware

BADCALL is a Trojan malware variant used by the group Lazarus Group.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

BADCALL uses a FakeTLS method during C2.

T1016
System Network Configuration Discovery

BADCALL collects the network adapter information.

T1082
System Information Discovery

BADCALL collects the computer name and host name on the compromised system.

T1090
Proxy

BADCALL functions as a proxy server between the victim and C2 server.

T1112
Modify Registry

BADCALL modifies the firewall Registry key SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfileGloballyOpenPorts\\List.

T1571
Non-Standard Port

BADCALL communicates on ports 443 and 8000 with a FakeTLS method.

T1573.001
Symmetric Cryptography

BADCALL encrypts C2 traffic using an XOR/ADD cipher.

T1686.003
Windows Host Firewall

BADCALL disables the Windows firewall before binding to a port.

Groups that use it1

Campaigns0

None recorded.

References1

  1. US-CERT BADCALL Open source
    US-CERT. (2018, February 06). Malware Analysis Report (MAR) - 10135536-G. Retrieved June 7, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.