ATT&CKSoftwareFlawedAmmyy

FlawedAmmyy

S0381

Malware.View on attack.mitre.org

About this malware

FlawedAmmyy is a remote access tool (RAT) that was first seen in early 2016. The code for FlawedAmmyy was based on leaked source code for a version of Ammyy Admin, a remote access software.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1001
Data Obfuscation

FlawedAmmyy may obfuscate portions of the initial C2 handshake.

T1005
Data from Local System

FlawedAmmyy has collected information and files from a compromised machine.

T1033
System Owner/User Discovery

FlawedAmmyy enumerates the current user during the initial infection.

T1041
Exfiltration Over C2 Channel

FlawedAmmyy has sent data collected from a compromised host to its C2 servers.

T1047
Windows Management Instrumentation

FlawedAmmyy leverages WMI to enumerate anti-virus on the victim.

T1056
Input Capture

FlawedAmmyy can collect mouse events.

T1056.001
Keylogging

FlawedAmmyy can collect keyboard events.

T1059.001
PowerShell

FlawedAmmyy has used PowerShell to execute commands.

T1059.003
Windows Command Shell

FlawedAmmyy has used `cmd` to execute commands on a compromised host.

T1069.001
Local Groups

FlawedAmmyy enumerates the privilege level of the victim during the initial infection.

T1070.004
File Deletion

FlawedAmmyy can execute batch scripts to delete files.

T1071.001
Web Protocols

FlawedAmmyy has used HTTP for C2.

T1082
System Information Discovery

FlawedAmmyy can collect the victim's operating system and computer name during the initial infection.

T1105
Ingress Tool Transfer

FlawedAmmyy can transfer files from C2.

T1113
Screen Capture

FlawedAmmyy can capture screenshots.

View all 22 procedure examples

Groups that use it2

Campaigns0

None recorded.

References1

  1. Proofpoint TA505 Mar 2018 Open source
    Proofpoint Staff. (2018, March 7). Leaked Ammyy Admin Source Code Turned into Malware. Retrieved May 28, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.