ATT&CKSoftwareBrave Prince

Brave Prince

S0252

Malware.View on attack.mitre.org

About this malware

Brave Prince is a Korean-language implant that was first observed in the wild in December 2017. It contains similar code and behavior to Gold Dragon, and was seen along with Gold Dragon and RunningRAT in operations surrounding the 2018 Pyeongchang Winter Olympics.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1012
Query Registry

Brave Prince gathers information about the Registry.

T1016
System Network Configuration Discovery

Brave Prince gathers network configuration information as well as the ARP cache.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

Some Brave Prince variants have used South Korea's Daum email service to exfiltrate information, and later variants have posted the data to a web server via an HTTP post command.

T1057
Process Discovery

Brave Prince lists the running processes.

T1082
System Information Discovery

Brave Prince collects hard drive content and system configuration information.

T1083
File and Directory Discovery

Brave Prince gathers file and directory information from the victim’s machine.

T1685
Disable or Modify Tools

Brave Prince terminates antimalware processes.

Groups that use it1

Campaigns0

None recorded.

References1

  1. McAfee Gold Dragon Open source
    Sherstobitoff, R., Saavedra-Morales, J. (2018, February 02). Gold Dragon Widens Olympics Malware Attacks, Gains Permanent Presence on Victims’ Systems. Retrieved June 6, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.