Malware.View on attack.mitre.org
NavRAT is a remote access tool designed to upload, download, and execute files. It has been observed in attacks targeting South Korea.
| Technique | Procedure example |
|---|---|
| T1055 Process Injection |
NavRAT copies itself into a running Internet Explorer process to evade detection. |
| T1056.001 Keylogging |
NavRAT logs the keystrokes on the targeted system. |
| T1057 Process Discovery |
NavRAT uses |
| T1059.003 Windows Command Shell |
NavRAT leverages cmd.exe to perform discovery techniques. NavRAT loads malicious shellcode and executes it in memory. |
| T1071.003 Mail Protocols |
NavRAT uses the email platform, Naver, for C2 communications, leveraging SMTP. |
| T1074.001 Local Data Staging |
NavRAT writes multiple outputs to a TMP file using the >> method. |
| T1082 System Information Discovery |
NavRAT uses |
| T1105 Ingress Tool Transfer |
NavRAT can download files remotely. |
| T1547.001 Registry Run Keys / Startup Folder |
NavRAT creates a Registry key to ensure a file gets executed upon reboot in order to establish persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.