Seasalt

S0345

Malware.View on attack.mitre.org

About this malware

Seasalt is malware that has been linked to APT1's 2010 operations. It shares some code similarities with OceanSalt.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Seasalt obfuscates configuration data.

T1036.004
Masquerade Task or Service

Seasalt has masqueraded as a service called "SaSaut" with a display name of "System Authorization Service" in an apparent attempt to masquerade as a legitimate service.

T1057
Process Discovery

Seasalt has a command to perform a process listing.

T1059.003
Windows Command Shell

Seasalt uses cmd.exe to create a reverse shell on the infected endpoint.

T1070.004
File Deletion

Seasalt has a command to delete a specified file.

T1071.001
Web Protocols

Seasalt uses HTTP for C2 communications.

T1083
File and Directory Discovery

Seasalt has the capability to identify the drive type on a victim.

T1105
Ingress Tool Transfer

Seasalt has a command to download additional files.

T1543.003
Windows Service

Seasalt is capable of installing itself as a service.

T1547.001
Registry Run Keys / Startup Folder

Seasalt creates a Registry entry to ensure infection after reboot under HKLM\Software\Microsoft\Windows\currentVersion\Run.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Mandiant APT1 Appendix Open source
    Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.
  2. McAfee Oceansalt Oct 2018 Open source
    Sherstobitoff, R., Malhotra, A. (2018, October 18). ‘Operation Oceansalt’ Attacks South Korea, U.S., and Canada With Source Code From Chinese Hacker Group. Retrieved November 30, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.