HyperBro

S0398

Malware.View on attack.mitre.org

About this malware

HyperBro is a custom in-memory backdoor used by Threat Group-3390.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1007
System Service Discovery

HyperBro can list all services and their configurations.

T1027.002
Software Packing

HyperBro has the ability to pack its payload.

T1027.013
Encrypted/Encoded File

HyperBro can be delivered encrypted to a compromised host.

T1055
Process Injection

HyperBro can run shellcode it injects into a newly created process.

T1070.004
File Deletion

HyperBro has the ability to delete a specified file.

T1071.001
Web Protocols

HyperBro has used HTTPS for C2 communications.

T1105
Ingress Tool Transfer

HyperBro has the ability to download additional files.

T1106
Native API

HyperBro has the ability to run an application (CreateProcessW) or script/file (ShellExecuteW) via API.

T1113
Screen Capture

HyperBro has the ability to take screenshots.

T1140
Deobfuscate/Decode Files or Information

HyperBro can unpack and decrypt its payload prior to execution.

T1569.002
Service Execution

HyperBro has the ability to start and stop a specified service.

T1574.001
DLL

HyperBro has used a legitimate application to sideload a DLL to decrypt, decompress, and run a payload.

Groups that use it1

Campaigns0

None recorded.

References3

  1. Hacker News LuckyMouse June 2018 Open source
    Khandelwal, S. (2018, June 14). Chinese Hackers Carried Out Country-Level Watering Hole Attack. Retrieved August 18, 2018.
  2. Securelist LuckyMouse June 2018 Open source
    Legezo, D. (2018, June 13). LuckyMouse hits national data center to organize country-level waterholing campaign. Retrieved August 18, 2018.
  3. Unit42 Emissary Panda May 2019 Open source
    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.