Koadic

S0250

Tool.View on attack.mitre.org

About this tool

Koadic is a Windows post-exploitation framework and penetration testing tool that is publicly available on GitHub. Koadic has several options for staging payloads and creating implants, and performs most of its operations using Windows Script Host.

Techniques used27

Procedure examples27

TechniqueProcedure example
T1003.002
Security Account Manager

Koadic can gather hashed passwords by dumping SAM/SECURITY hive.

T1003.003
NTDS

Koadic can gather hashed passwords by gathering domain controller hashes from NTDS.

T1005
Data from Local System

Koadic can download files off the target system to send back to the server.

T1016
System Network Configuration Discovery

Koadic can retrieve the contents of the IP routing table as well as information about the Windows domain.

T1021.001
Remote Desktop Protocol

Koadic can enable remote desktop on the victim's machine.

T1033
System Owner/User Discovery

Koadic can identify logged in users across the domain and views user sessions.

T1046
Network Service Discovery

Koadic can scan for open TCP ports on the target network.

T1047
Windows Management Instrumentation

Koadic can use WMI to execute commands.

T1053.005
Scheduled Task

Koadic has used scheduled tasks to add persistence.

T1055.001
Dynamic-link Library Injection

Koadic can perform process injection by using a reflective DLL.

T1059.001
PowerShell

Koadic has used PowerShell to establish persistence.

T1059.003
Windows Command Shell

Koadic can open an interactive command-shell to perform command line functions on victim machines. Koadic performs most of its operations using Windows Script Host (Jscript) and to run arbitrary shellcode.

T1059.005
Visual Basic

Koadic performs most of its operations using Windows Script Host (VBScript) and runs arbitrary shellcode .

T1071.001
Web Protocols

Koadic has used HTTP for C2 communications.

T1082
System Information Discovery

Koadic can obtain the OS version and build, computer name, and processor architecture from a compromised host.

View all 27 procedure examples

Groups that use it4

Campaigns0

None recorded.

References3

  1. Github Koadic Open source
    Magius, J., et al. (2017, July 19). Koadic. Retrieved September 27, 2024.
  2. MalwareBytes LazyScripter Feb 2021 Open source
    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.
  3. Palo Alto Sofacy 06-2018 Open source
    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.