yty

S0248

Malware.View on attack.mitre.org

About this malware

yty is a modular, plugin-based malware framework. The components of the framework are written in a variety of programming languages.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

yty collects files with the following extensions: .ppt, .pptx, .pdf, .doc, .docx, .xls, .xlsx, .docm, .rtf, .inp, .xlsm, .csv, .odt, .pps, .vcf and sends them back to the C2 server.

T1016
System Network Configuration Discovery

yty runs ipconfig /all and collects the domain name.

T1018
Remote System Discovery

yty uses the net view command for discovery.

T1027.002
Software Packing

yty packs a plugin with UPX.

T1027.016
Junk Code Insertion

yty contains junk code in its binary, likely to confuse malware analysts.

T1033
System Owner/User Discovery

yty collects the victim’s username.

T1053.005
Scheduled Task

yty establishes persistence by creating a scheduled task with the command SchTasks /Create /SC DAILY /TN BigData /TR “ + path_file + “/ST 09:30“.

T1056.001
Keylogging

yty uses a keylogger plugin to gather keystrokes.

T1057
Process Discovery

yty gets an output of running processes using the tasklist command.

T1082
System Information Discovery

yty gathers the computer name, CPU information, Microsoft Windows version, and runs the command systeminfo.

T1083
File and Directory Discovery

yty gathers information on victim’s drives and has a plugin for document listing.

T1102.002
Bidirectional Communication

yty communicates to the C2 server by retrieving a Google Doc.

T1113
Screen Capture

yty collects screenshots of the victim machine.

T1497.001
System Checks

yty has some basic anti-sandbox detection that tries to detect Virtual PC, Sandboxie, and VMware.

T1680
Local Storage Discovery

yty gathers the the serial number of the main disk volume.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. ASERT Donot March 2018 Open source
    Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.