ATT&CKSoftwareRogueRobin

RogueRobin

S0270

Malware.View on attack.mitre.org

About this malware

RogueRobin is a payload used by DarkHydrus that has been developed in PowerShell and C#.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1016
System Network Configuration Discovery

RogueRobin gathers the IP address and domain from the victim’s machine.

T1027.010
Command Obfuscation

The PowerShell script with the RogueRobin payload was obfuscated using the COMPRESS technique in `Invoke-Obfuscation`.

T1033
System Owner/User Discovery

RogueRobin collects the victim’s username and whether that user is an admin.

T1047
Windows Management Instrumentation

RogueRobin uses various WMI queries to check if the sample is running in a sandbox.

T1057
Process Discovery

RogueRobin checks the running processes for evidence it may be running in a sandbox environment. It specifically enumerates processes for Wireshark and Sysinternals.

T1059.001
PowerShell

RogueRobin uses a command prompt to run a PowerShell script from Excel. To assist in establishing persistence, RogueRobin creates %APPDATA%\OneDrive.bat and saves the following string to it:powershell.exe -WindowStyle Hidden -exec bypass -File “%APPDATA%\OneDrive.ps1”.

T1059.003
Windows Command Shell

RogueRobin uses Windows Script Components.

T1082
System Information Discovery

RogueRobin gathers BIOS versions and manufacturers, the number of CPU cores, the total physical memory, and the computer name.

T1102.002
Bidirectional Communication

RogueRobin has used Google Drive as a Command and Control channel.

T1105
Ingress Tool Transfer

RogueRobin can save a new file to the system from the C2 server.

T1113
Screen Capture

RogueRobin has a command named $screenshot that may be responsible for taking screenshots of the victim machine.

T1132.001
Standard Encoding

RogueRobin base64 encodes strings that are sent to the C2 over its DNS tunnel.

T1140
Deobfuscate/Decode Files or Information

RogueRobin decodes an embedded executable using base64 and decompresses it.

T1218.010
Regsvr32

RogueRobin uses regsvr32.exe to run a .sct file for execution.

T1497.001
System Checks

RogueRobin uses WMI to check BIOS version for VBOX, bochs, qemu, virtualbox, and vm to check for evidence that the script might be executing within an analysis environment.

View all 18 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Unit 42 DarkHydrus July 2018 Open source
    Falcone, R., et al. (2018, July 27). New Threat Actor Group DarkHydrus Targets Middle East Government. Retrieved August 2, 2018.
  2. Unit42 DarkHydrus Jan 2019 Open source
    Lee, B., Falcone, R. (2019, January 18). DarkHydrus delivers new Trojan that can use Google Drive for C2 communications. Retrieved April 17, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.