FELIXROOT

S0267

Malware.View on attack.mitre.org

About this malware

FELIXROOT is a backdoor that has been used to target Ukrainian victims.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1012
Query Registry

FELIXROOT queries the Registry for specific keys for potential privilege escalation and proxy information. FELIXROOT has also used WMI to query the Windows Registry.

T1016
System Network Configuration Discovery

FELIXROOT collects information about the network including the IP address and DHCP server.

T1027.013
Encrypted/Encoded File

FELIXROOT encrypts strings in the backdoor using a custom XOR algorithm.

T1033
System Owner/User Discovery

FELIXROOT collects the username from the victim’s machine.

T1047
Windows Management Instrumentation

FELIXROOT uses WMI to query the Windows Registry.

T1057
Process Discovery

FELIXROOT collects a list of running processes.

T1059.003
Windows Command Shell

FELIXROOT executes batch scripts on the victim’s machine, and can launch a reverse shell for command execution.

T1070.004
File Deletion

FELIXROOT deletes the .LNK file from the startup directory as well as the dropper components.

T1071.001
Web Protocols

FELIXROOT uses HTTP and HTTPS to communicate with the C2 server.

T1082
System Information Discovery

FELIXROOT collects the victim’s computer name, processor architecture, OS version, and system type.

T1105
Ingress Tool Transfer

FELIXROOT downloads and uploads files to and from the victim’s machine.

T1112
Modify Registry

FELIXROOT deletes the Registry key HKCU\Software\Classes\Applications\rundll32.exe\shell\open.

T1124
System Time Discovery

FELIXROOT gathers the time zone information from the victim’s machine.

T1218.011
Rundll32

FELIXROOT uses Rundll32 for executing the dropper program.

T1518.001
Security Software Discovery

FELIXROOT checks for installed security software like antivirus and firewall.

View all 19 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. FireEye FELIXROOT July 2018 Open source
    Patil, S. (2018, June 26). Microsoft Office Vulnerabilities Used to Distribute FELIXROOT Backdoor in Recent Campaign. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.