Malware.View on attack.mitre.org
Kazuar is a fully featured, multi-platform backdoor Trojan written using the Microsoft .NET framework.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Kazuar uploads files from a specified directory to the C2 server. |
| T1008 Fallback Channels |
Kazuar can accept multiple URLs for C2 servers. |
| T1010 Application Window Discovery |
Kazuar gathers information about opened windows. |
| T1016 System Network Configuration Discovery |
Kazuar gathers information about network adapters. |
| T1027 Obfuscated Files or Information |
Kazuar is obfuscated using the open source ConfuserEx protector. Kazuar also obfuscates the name of created files/folders/mutexes and encrypts debug messages written to log files using the Rijndael cipher. |
| T1029 Scheduled Transfer |
Kazuar can sleep for a specific time and be set to communicate at specific intervals. |
| T1033 System Owner/User Discovery |
Kazuar gathers information on users. |
| T1047 Windows Management Instrumentation |
Kazuar obtains a list of running processes through WMI querying. |
| T1055.001 Dynamic-link Library Injection |
If running in a Windows environment, Kazuar saves a DLL to disk that is injected into the explorer.exe process to execute the payload. Kazuar can also be configured to inject and execute within specific processes. |
| T1057 Process Discovery |
Kazuar obtains a list of running processes through WMI querying and the |
| T1059.003 Windows Command Shell |
Kazuar uses cmd.exe to execute commands on the victim’s machine. |
| T1059.004 Unix Shell |
Kazuar uses /bin/bash to execute commands on the victim’s machine. |
| T1069.001 Local Groups |
Kazuar gathers information about local groups and members. |
| T1070.004 File Deletion |
Kazuar can delete files. |
| T1071.001 Web Protocols |
Kazuar uses HTTP and HTTPS to communicate with the C2 server. Kazuar can also act as a webserver and listen for inbound HTTP requests through an exposed API. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.