Bisonal

S0268

Malware.View on attack.mitre.org

About this malware

Bisonal is a remote access tool (RAT) that has been used by Tonto Team against public and private sector organizations in Russia, South Korea, and Japan since at least December 2010.

Techniques used34

Procedure examples34

TechniqueProcedure example
T1005
Data from Local System

Bisonal has collected information from a compromised host.

T1012
Query Registry

Bisonal has used the RegQueryValueExA function to retrieve proxy information in the Registry.

T1016
System Network Configuration Discovery

Bisonal can execute ipconfig on the victim’s machine.

T1027.001
Binary Padding

Bisonal has appended random binary data to the end of itself to generate a large binary.

T1027.002
Software Packing

Bisonal has used the MPRESS packer and similar tools for obfuscation.

T1027.013
Encrypted/Encoded File

Bisonal's DLL file and non-malicious decoy file are encrypted with RC4 and some function name strings are obfuscated.

T1036
Masquerading

Bisonal dropped a decoy payload with a .jpg extension that contained a malicious Visual Basic script.

T1036.005
Match Legitimate Resource Name or Location

Bisonal has renamed malicious code to `msacm32.dll` to hide within a legitimate library; earlier versions were disguised as `winhelp`.

T1041
Exfiltration Over C2 Channel

Bisonal has added the exfiltrated data to the URL over the C2 channel.

T1057
Process Discovery

Bisonal can obtain a list of running processes on the victim’s machine.

T1059.003
Windows Command Shell

Bisonal has launched cmd.exe and used the ShellExecuteW() API function to execute commands on the system.

T1059.005
Visual Basic

Bisonal's dropper creates VBS scripts on the victim’s machine.

T1070.004
File Deletion

Bisonal will delete its dropper and VBS scripts from the victim’s machine.

T1071.001
Web Protocols

Bisonal has used HTTP for C2 communications.

T1082
System Information Discovery

Bisonal has used commands and API calls to gather system information.

View all 34 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Talos Bisonal Mar 2020 Open source
    Mercer, W., et al. (2020, March 5). Bisonal: 10 years of play. Retrieved January 26, 2022.
  2. Unit 42 Bisonal July 2018 Open source
    Hayashi, K., Ray, V. (2018, July 31). Bisonal Malware Used in Attacks Against Russia and South Korea. Retrieved August 7, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.