ATT&CKSoftwareHotCroissant

HotCroissant

S0431

Malware.View on attack.mitre.org

About this malware

HotCroissant is a remote access trojan (RAT) attributed by U.S. government entities to malicious North Korean government cyber activity, tracked collectively as HIDDEN COBRA. HotCroissant shares numerous code similarities with Rifdoor.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1007
System Service Discovery

HotCroissant has the ability to retrieve a list of services on the infected host.

T1010
Application Window Discovery

HotCroissant has the ability to list the names of all open windows on the infected host.

T1016
System Network Configuration Discovery

HotCroissant has the ability to identify the IP address of the compromised machine.

T1027.002
Software Packing

HotCroissant has used the open source UPX executable packer.

T1027.013
Encrypted/Encoded File

HotCroissant has encrypted strings with single-byte XOR and base64 encoded RC4.

T1033
System Owner/User Discovery

HotCroissant has the ability to collect the username on the infected host.

T1041
Exfiltration Over C2 Channel

HotCroissant has the ability to download files from the infected host to the command and control (C2) server.

T1053.005
Scheduled Task

HotCroissant has attempted to install a scheduled task named “Java Maintenance64” on startup to establish persistence.

T1057
Process Discovery

HotCroissant has the ability to list running processes on the infected host.

T1059.003
Windows Command Shell

HotCroissant can remotely open applications on the infected host with the ShellExecuteA command.

T1070.004
File Deletion

HotCroissant has the ability to clean up installed files, delete files, and delete itself from the victim’s machine.

T1082
System Information Discovery

HotCroissant has the ability to determine if the current user is an administrator, Windows product name, processor name, screen resolution, and physical RAM of the infected host.

T1083
File and Directory Discovery

HotCroissant has the ability to retrieve a list of files in a given directory as well as drives and drive types.

T1105
Ingress Tool Transfer

HotCroissant has the ability to upload a file from the command and control (C2) server to the victim machine.

T1106
Native API

HotCroissant can perform dynamic DLL importing and API lookups using LoadLibrary and GetProcAddress on obfuscated strings.

View all 20 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Carbon Black HotCroissant April 2020 Open source
    Knight, S.. (2020, April 16). VMware Carbon Black TAU Threat Analysis: The Evolution of Lazarus. Retrieved May 1, 2020.
  2. US-CERT HOTCROISSANT February 2020 Open source
    US-CERT. (2020, February 20). MAR-10271944-1.v1 – North Korean Trojan: HOTCROISSANT. Retrieved May 1, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.