Xbash

S0341

Malware.View on attack.mitre.org

About this malware

Xbash is a malware family that has targeted Linux and Microsoft Windows servers. The malware has been tied to the Iron Group, a threat actor group known for previous ransomware attacks. Xbash was developed in Python and then converted into a self-contained Linux ELF executable by using PyInstaller.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1016
System Network Configuration Discovery

Xbash can collect IP addresses and local intranet information from a victim’s machine.

T1046
Network Service Discovery

Xbash can perform port scanning of TCP and UDP ports.

T1053.003
Cron

Xbash can create a cronjob for persistence if it determines it is on a Linux system.

T1059.001
PowerShell

Xbash can use scripts to invoke PowerShell to download a malicious PE executable or PE DLL for execution.

T1059.005
Visual Basic

Xbash can execute malicious VBScript payloads on the victim’s machine.

T1059.007
JavaScript

Xbash can execute malicious JavaScript payloads on the victim’s machine.

T1071.001
Web Protocols

Xbash uses HTTP for C2 communications.

T1102.001
Dead Drop Resolver

Xbash can obtain a webpage hosted on Pastebin to update its C2 domain list.

T1105
Ingress Tool Transfer

Xbash can download additional malicious files from its C2 server.

T1110.001
Password Guessing

Xbash can obtain a list of weak passwords from the C2 server to use for brute forcing as well as attempt to brute force services with open ports.

T1203
Exploitation for Client Execution

Xbash can attempt to exploit known vulnerabilities in Hadoop, Redis, or ActiveMQ when it finds those services running in order to conduct further execution.

T1218.005
Mshta

Xbash can use mshta for executing scripts.

T1218.010
Regsvr32

Xbash can use regsvr32 for executing scripts.

T1485
Data Destruction

Xbash has destroyed Linux-based databases as part of its ransomware capabilities.

T1486
Data Encrypted for Impact

Xbash has maliciously encrypted victim's database systems and demanded a cryptocurrency ransom be paid.

View all 16 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Unit42 Xbash Sept 2018 Open source
    Xiao, C. (2018, September 17). Xbash Combines Botnet, Ransomware, Coinmining in Worm that Targets Linux and Windows. Retrieved November 14, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.