Malware.View on attack.mitre.org
InvisiMole is a modular spyware program that has been used by the InvisiMole Group since at least 2013. InvisiMole has two backdoor modules called RC2FM and RC2CL that are used to perform post-exploitation activities. It has been discovered on compromised victims in the Ukraine and Russia. Gamaredon Group infrastructure has been used to download and execute InvisiMole against a small number of victims.
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP. |
| T1005 Data from Local System |
InvisiMole can collect data from the system, and can monitor changes in specified directories. |
| T1007 System Service Discovery |
InvisiMole can obtain running services on the victim. |
| T1008 Fallback Channels |
InvisiMole has been configured with several servers available for alternate C2 communications. |
| T1010 Application Window Discovery |
InvisiMole can enumerate windows and child windows on a compromised host. |
| T1012 Query Registry |
InvisiMole can enumerate Registry values, keys, and data. |
| T1016 System Network Configuration Discovery |
InvisiMole gathers information on the IP forwarding table, MAC address, configured proxy, and network SSID. |
| T1025 Data from Removable Media |
InvisiMole can collect jpeg files from connected MTP devices. |
| T1027 Obfuscated Files or Information |
InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format. |
| T1027.005 Indicator Removal from Tools |
InvisiMole has undergone regular technical improvements in an attempt to evade detection. |
| T1033 System Owner/User Discovery |
InvisiMole lists local users and session information. |
| T1036.004 Masquerade Task or Service |
InvisiMole has attempted to disguise itself by registering under a seemingly legitimate service name. |
| T1036.005 Match Legitimate Resource Name or Location |
InvisiMole has disguised its droppers as legitimate software or documents, matching their original names and locations, and saved its files as mpr.dll in the Windows folder. |
| T1046 Network Service Discovery |
InvisiMole can scan the network for open ports and vulnerable instances of RDP and SMB protocols. |
| T1053.005 Scheduled Task |
InvisiMole has used scheduled tasks named |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.