BabyShark

S0414

Malware.View on attack.mitre.org

About this malware

BabyShark is a Microsoft Visual Basic (VB) script-based malware family that is believed to be associated with several North Korean campaigns.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1012
Query Registry

BabyShark has executed the reg query command for HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default.

T1016
System Network Configuration Discovery

BabyShark has executed the ipconfig /all command.

T1033
System Owner/User Discovery

BabyShark has executed the whoami command.

T1053.005
Scheduled Task

BabyShark has used scheduled tasks to maintain persistence.

T1056.001
Keylogging

BabyShark has a PowerShell-based remote administration ability that can implement a PowerShell or C# based keylogger.

T1057
Process Discovery

BabyShark has executed the tasklist command.

T1059.003
Windows Command Shell

BabyShark has used cmd.exe to execute commands.

T1059.005
Visual Basic

BabyShark can execute additional VisualBasic content.

T1070.004
File Deletion

BabyShark has cleaned up all files associated with the secondary payload execution.

T1082
System Information Discovery

BabyShark has executed the ver command.

T1083
File and Directory Discovery

BabyShark has used dir to search for "programfiles" and "appdata".

T1105
Ingress Tool Transfer

BabyShark has downloaded additional files from the C2.

T1132.001
Standard Encoding

BabyShark has encoded data using certutil before exfiltration.

T1140
Deobfuscate/Decode Files or Information

BabyShark has the ability to decode downloaded files prior to execution.

T1218.005
Mshta

BabyShark has used mshta.exe to download and execute applications from a remote server.

View all 16 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit42 BabyShark Feb 2019 Open source
    Unit 42. (2019, February 22). New BabyShark Malware Targets U.S. National Security Think Tanks. Retrieved October 7, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.