Zebrocy

S0251

Malware.View on attack.mitre.org

About this malware

Zebrocy is a Trojan that has been used by APT28 since at least November 2015. The malware comes in several programming language variants, including C++, Delphi, AutoIt, C#, VB.NET, and Golang.

Techniques used31

Procedure examples31

TechniqueProcedure example
T1012
Query Registry

Zebrocy executes the reg query command to obtain information in the Registry.

T1016
System Network Configuration Discovery

Zebrocy runs the ipconfig /all command.

T1027.002
Software Packing

Zebrocy's Delphi variant was packed with UPX.

T1033
System Owner/User Discovery

Zebrocy gets the username from the system.

T1037.001
Logon Script (Windows)

Zebrocy performs persistence with a logon script via adding to the Registry key HKCU\Environment\UserInitMprLogonScript.

T1041
Exfiltration Over C2 Channel

Zebrocy has exfiltrated data to the designated C2 server using HTTP POST requests.

T1047
Windows Management Instrumentation

One variant of Zebrocy uses WMI queries to gather information.

T1049
System Network Connections Discovery

Zebrocy uses netstat -aon to gather network connection information.

T1053.005
Scheduled Task

Zebrocy has a command to create a scheduled task for persistence.

T1056.004
Credential API Hooking

Zebrocy installs an application-defined Windows hook to get notified when a network drive has been attached, so it can then use the hook to call its RecordToFile file stealing method.

T1057
Process Discovery

Zebrocy uses the tasklist and wmic process get Capture, ExecutablePath commands to gather the processes running on the system.

T1059.003
Windows Command Shell

Zebrocy uses cmd.exe to execute commands on the system.

T1070.004
File Deletion

Zebrocy has a command to delete files and directories.

T1071.001
Web Protocols

Zebrocy uses HTTP for C2.

T1071.003
Mail Protocols

Zebrocy uses SMTP and POP3 for C2.

View all 31 procedure examples

Groups that use it1

Campaigns0

None recorded.

References4

  1. CISA Zebrocy Oct 2020 Open source
    CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.
  2. Palo Alto Sofacy 06-2018 Open source
    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.
  3. Unit42 Cannon Nov 2018 Open source
    Falcone, R., Lee, B. (2018, November 20). Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan. Retrieved November 26, 2018.
  4. Unit42 Sofacy Dec 2018 Open source
    Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.