Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
jRAT can list local services. |
| T1016 System Network Configuration Discovery |
jRAT can gather victim internal and external IPs. |
| T1021.001 Remote Desktop Protocol |
jRAT can support RDP control. |
| T1027 Obfuscated Files or Information |
jRAT’s Java payload is encrypted with AES. Additionally, backdoor files are encrypted using DES as a stream cipher. Later variants of jRAT also incorporated AV evasion methods such as Java bytecode obfuscation via the commercial Allatori obfuscation tool. |
| T1027.002 Software Packing |
jRAT payloads have been packed. |
| T1029 Scheduled Transfer |
jRAT can be configured to reconnect at certain intervals. |
| T1037.005 Startup Items |
jRAT can list and manage startup entries. |
| T1047 Windows Management Instrumentation |
jRAT uses WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details. |
| T1049 System Network Connections Discovery |
jRAT can list network connections. |
| T1056.001 Keylogging |
jRAT has the capability to log keystrokes from the victim’s machine, both offline and online. |
| T1057 Process Discovery |
jRAT can query and kill system processes. |
| T1059.003 Windows Command Shell |
jRAT has command line access. |
| T1059.005 Visual Basic |
jRAT has been distributed as HTA files with VBScript. |
| T1059.007 JavaScript |
jRAT has been distributed as HTA files with JScript. |
| T1070.004 File Deletion |
jRAT has a function to delete files from the victim’s machine. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.