KEYMARBLE

S0271

Malware.View on attack.mitre.org

About this malware

KEYMARBLE is a Trojan that has reportedly been used by the North Korean government.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1016
System Network Configuration Discovery

KEYMARBLE gathers the MAC address of the victim’s machine.

T1057
Process Discovery

KEYMARBLE can obtain a list of running processes on the system.

T1059.003
Windows Command Shell

KEYMARBLE can execute shell commands using cmd.exe.

T1070.004
File Deletion

KEYMARBLE has the capability to delete files off the victim’s machine.

T1082
System Information Discovery

KEYMARBLE has the capability to collect the computer name, language settings, the OS version, CPU information, and time elapsed since system start.

T1083
File and Directory Discovery

KEYMARBLE has a command to search for files on the victim’s machine.

T1105
Ingress Tool Transfer

KEYMARBLE can upload files to the victim’s machine and can download additional payloads.

T1112
Modify Registry

KEYMARBLE has a command to create Registry entries for storing data under HKEY_CURRENT_USER\SOFTWARE\Microsoft\WABE\DataPath.

T1113
Screen Capture

KEYMARBLE can capture screenshots of the victim’s machine.

T1573.001
Symmetric Cryptography

KEYMARBLE uses a customized XOR algorithm to encrypt C2 communications.

T1680
Local Storage Discovery

KEYMARBLE has the capability to collect information on disk devices.

Groups that use it1

Campaigns0

None recorded.

References1

  1. US-CERT KEYMARBLE Aug 2018 Open source
    US-CERT. (2018, August 09). MAR-10135536-17 – North Korean Trojan: KEYMARBLE. Retrieved August 16, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.