AuditCred

S0347

Malware.View on attack.mitre.org

About this malware

AuditCred is a malicious DLL that has been used by Lazarus Group during their 2018 attacks.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

AuditCred encrypts the configuration.

T1055
Process Injection

AuditCred can inject code from files to other running processes.

T1059.003
Windows Command Shell

AuditCred can open a reverse shell on the system to execute commands.

T1070.004
File Deletion

AuditCred can delete files from the system.

T1083
File and Directory Discovery

AuditCred can search through folders and files on the system.

T1090
Proxy

AuditCred can utilize proxy for communications.

T1105
Ingress Tool Transfer

AuditCred can download files and additional malware.

T1140
Deobfuscate/Decode Files or Information

AuditCred uses XOR and RC4 to perform decryption on the code functions.

T1543.003
Windows Service

AuditCred is installed as a new service on the system.

Groups that use it1

Campaigns0

None recorded.

References1

  1. TrendMicro Lazarus Nov 2018 Open source
    Trend Micro. (2018, November 20). Lazarus Continues Heists, Mounts Attacks on Financial Organizations in Latin America. Retrieved December 3, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.