Malware.View on attack.mitre.org
PoetRAT is a remote access trojan (RAT) that was first identified in April 2020. PoetRAT has been used in multiple campaigns against the private and public sectors in Azerbaijan, including ICS and SCADA systems in the energy sector. The STIBNITE activity group has been observed using the malware. PoetRAT derived its name from references in the code to poet William Shakespeare.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
PoetRAT used voStro.exe, a compiled pypykatz (Python version of Mimikatz), to steal credentials. |
| T1018 Remote System Discovery |
PoetRAT used Nmap for remote system discovery. |
| T1027 Obfuscated Files or Information |
PoetRAT has used a custom encryption scheme for communication between scripts. |
| T1027.010 Command Obfuscation |
PoetRAT has `pyminifier` to obfuscate scripts. |
| T1033 System Owner/User Discovery |
PoetRAT sent username, computer name, and the previously generated UUID in reply to a "who" command from C2. |
| T1041 Exfiltration Over C2 Channel |
PoetRAT has exfiltrated data over the C2 channel. |
| T1048 Exfiltration Over Alternative Protocol |
PoetRAT has used a .NET tool named dog.exe to exiltrate information over an e-mail account. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
|
| T1056.001 Keylogging |
PoetRAT has used a Python tool named klog.exe for keylogging. |
| T1057 Process Discovery |
PoetRAT has the ability to list all running processes. |
| T1059.003 Windows Command Shell |
PoetRAT has called cmd through a Word document macro. |
| T1059.005 Visual Basic |
PoetRAT has used Word documents with VBScripts to execute malicious activities. |
| T1059.006 Python |
PoetRAT was executed with a Python script and worked in conjunction with additional Python-based post-exploitation tools. |
| T1059.011 Lua |
PoetRAT has executed a Lua script through a Lua interpreter for Windows. |
| T1070.004 File Deletion |
PoetRAT has the ability to overwrite scripts and delete itself if a sandbox environment is detected. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.