NavRAT

S0247

Malware.View on attack.mitre.org

About this malware

NavRAT is a remote access tool designed to upload, download, and execute files. It has been observed in attacks targeting South Korea.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1055
Process Injection

NavRAT copies itself into a running Internet Explorer process to evade detection.

T1056.001
Keylogging

NavRAT logs the keystrokes on the targeted system.

T1057
Process Discovery

NavRAT uses tasklist /v to check running processes.

T1059.003
Windows Command Shell

NavRAT leverages cmd.exe to perform discovery techniques. NavRAT loads malicious shellcode and executes it in memory.

T1071.003
Mail Protocols

NavRAT uses the email platform, Naver, for C2 communications, leveraging SMTP.

T1074.001
Local Data Staging

NavRAT writes multiple outputs to a TMP file using the >> method.

T1082
System Information Discovery

NavRAT uses systeminfo on a victim’s machine.

T1105
Ingress Tool Transfer

NavRAT can download files remotely.

T1547.001
Registry Run Keys / Startup Folder

NavRAT creates a Registry key to ensure a file gets executed upon reboot in order to establish persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Talos NavRAT May 2018 Open source
    Mercer, W., Rascagneres, P. (2018, May 31). NavRAT Uses US-North Korea Summit As Decoy For Attacks In South Korea. Retrieved June 11, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.