Malware.View on attack.mitre.org
Cardinal RAT is a potentially low volume remote access trojan (RAT) observed since December 2015. Cardinal RAT is notable for its unique utilization of uncompiled C# source code and the Microsoft Windows built-in csc.exe compiler.
| Technique | Procedure example |
|---|---|
| T1008 Fallback Channels |
Cardinal RAT can communicate over multiple C2 host and port combinations. |
| T1012 Query Registry |
Cardinal RAT contains watchdog functionality that periodically ensures |
| T1027.004 Compile After Delivery |
Cardinal RAT and its watchdog component are compiled and executed after being delivered to victims as embedded, uncompiled source code. |
| T1027.013 Encrypted/Encoded File |
Cardinal RAT encodes many of its artifacts and is encrypted (AES-128) when downloaded. |
| T1033 System Owner/User Discovery |
Cardinal RAT can collect the username from a victim machine. |
| T1055 Process Injection |
Cardinal RAT injects into a newly spawned process created from a native Windows executable. |
| T1056.001 Keylogging |
Cardinal RAT can log keystrokes. |
| T1057 Process Discovery |
Cardinal RAT contains watchdog functionality that ensures its process is always running, else spawns a new instance. |
| T1059.003 Windows Command Shell |
Cardinal RAT can execute commands. |
| T1070.004 File Deletion |
Cardinal RAT can uninstall itself, including deleting its executable. |
| T1071.001 Web Protocols |
Cardinal RAT is downloaded using HTTP over port 443. |
| T1082 System Information Discovery |
Cardinal RAT can collect the hostname, Microsoft Windows version, and processor architecture from a victim machine. |
| T1083 File and Directory Discovery |
Cardinal RAT checks its current working directory upon execution and also contains watchdog functionality that ensures its executable is located in the correct path (else it will rewrite the payload). |
| T1090 Proxy |
Cardinal RAT can act as a reverse proxy. |
| T1105 Ingress Tool Transfer |
Cardinal RAT can download and execute additional payloads. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.