ATT&CKSoftwareCardinal RAT

Cardinal RAT

S0348

Malware.View on attack.mitre.org

About this malware

Cardinal RAT is a potentially low volume remote access trojan (RAT) observed since December 2015. Cardinal RAT is notable for its unique utilization of uncompiled C# source code and the Microsoft Windows built-in csc.exe compiler.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1008
Fallback Channels

Cardinal RAT can communicate over multiple C2 host and port combinations.

T1012
Query Registry

Cardinal RAT contains watchdog functionality that periodically ensures HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load is set to point to its executable.

T1027.004
Compile After Delivery

Cardinal RAT and its watchdog component are compiled and executed after being delivered to victims as embedded, uncompiled source code.

T1027.013
Encrypted/Encoded File

Cardinal RAT encodes many of its artifacts and is encrypted (AES-128) when downloaded.

T1033
System Owner/User Discovery

Cardinal RAT can collect the username from a victim machine.

T1055
Process Injection

Cardinal RAT injects into a newly spawned process created from a native Windows executable.

T1056.001
Keylogging

Cardinal RAT can log keystrokes.

T1057
Process Discovery

Cardinal RAT contains watchdog functionality that ensures its process is always running, else spawns a new instance.

T1059.003
Windows Command Shell

Cardinal RAT can execute commands.

T1070.004
File Deletion

Cardinal RAT can uninstall itself, including deleting its executable.

T1071.001
Web Protocols

Cardinal RAT is downloaded using HTTP over port 443.

T1082
System Information Discovery

Cardinal RAT can collect the hostname, Microsoft Windows version, and processor architecture from a victim machine.

T1083
File and Directory Discovery

Cardinal RAT checks its current working directory upon execution and also contains watchdog functionality that ensures its executable is located in the correct path (else it will rewrite the payload).

T1090
Proxy

Cardinal RAT can act as a reverse proxy.

T1105
Ingress Tool Transfer

Cardinal RAT can download and execute additional payloads.

View all 22 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. PaloAlto CardinalRat Apr 2017 Open source
    Grunzweig, J.. (2017, April 20). Cardinal RAT Active for Over Two Years. Retrieved December 8, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.