ATT&CKSoftwareInvisiMole

InvisiMole

S0260

Malware.View on attack.mitre.org

About this malware

InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013. InvisiMole has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia. Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims.

Techniques used73

Procedure examples73

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP.

T1005
Data from Local System

InvisiMole can collect data from the system, and can monitor changes in specified directories.

T1007
System Service Discovery

InvisiMole can obtain running services on the victim.

T1008
Fallback Channels

InvisiMole has been configured with several servers available for alternate C2 communications.

T1010
Application Window Discovery

InvisiMole can enumerate windows and child windows on a compromised host.

T1012
Query Registry

InvisiMole can enumerate Registry values, keys, and data.

T1016
System Network Configuration Discovery

InvisiMole gathers information on the IP forwarding table, MAC address, configured proxy, and network SSID.

T1025
Data from Removable Media

InvisiMole can collect jpeg files from connected MTP devices.

T1027
Obfuscated Files or Information

InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format.

T1027.005
Indicator Removal from Tools

InvisiMole has undergone regular technical improvements in an attempt to evade detection.

T1033
System Owner/User Discovery

InvisiMole lists local users and session information.

T1036.004
Masquerade Task or Service

InvisiMole has attempted to disguise itself by registering under a seemingly legitimate service name.

T1036.005
Match Legitimate Resource Name or Location

InvisiMole has disguised its droppers as legitimate software or documents, matching their original names and locations, and saved its files as mpr.dll in the Windows folder.

T1046
Network Service Discovery

InvisiMole can scan the network for open ports and vulnerable instances of RDP and SMB protocols.

T1053.005
Scheduled Task

InvisiMole has used scheduled tasks named MSST and \Microsoft\Windows\Autochk\Scheduled to establish persistence.

View all 73 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. ESET InvisiMole June 2018 Open source
    Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.
  2. ESET InvisiMole June 2020 Open source
    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.