HAWKBALL

S0391

Malware.View on attack.mitre.org

About this malware

HAWKBALL is a backdoor that was observed in targeting of the government sector in Central Asia.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

HAWKBALL has encrypted the payload with an XOR-based algorithm.

T1033
System Owner/User Discovery

HAWKBALL can collect the user name of the system.

T1041
Exfiltration Over C2 Channel

HAWKBALL has sent system information and files over the C2 channel.

T1059.003
Windows Command Shell

HAWKBALL has created a cmd.exe reverse shell, executed commands, and uploaded output via the command line.

T1070.004
File Deletion

HAWKBALL has the ability to delete files.

T1071.001
Web Protocols

HAWKBALL has used HTTP to communicate with a single hard-coded C2 server.

T1082
System Information Discovery

HAWKBALL can collect the OS version, architecture information, and computer name.

T1106
Native API

HAWKBALL has leveraged several Windows API calls to create processes, gather disk information, and detect debugger activity.

T1203
Exploitation for Client Execution

HAWKBALL has exploited Microsoft Office vulnerabilities CVE-2017-11882 and CVE-2018-0802 to deliver the payload.

T1559.002
Dynamic Data Exchange

HAWKBALL has used an OLE object that uses Equation Editor to drop the embedded shellcode.

T1560.003
Archive via Custom Method

HAWKBALL has encrypted data with XOR before sending it over the C2 channel.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. FireEye HAWKBALL Jun 2019 Open source
    Patil, S. and Williams, M.. (2019, June 5). Government Sector in Central Asia Targeted With New HAWKBALL Backdoor Delivered via Microsoft Office Vulnerabilities. Retrieved June 20, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.