Rifdoor

S0433

Malware.View on attack.mitre.org

About this malware

Rifdoor is a remote access trojan (RAT) that shares numerous code similarities with HotCroissant.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1016
System Network Configuration Discovery

Rifdoor has the ability to identify the IP address of the compromised host.

T1027.001
Binary Padding

Rifdoor has added four additional bytes of data upon launching, then saved the changed version as C:\ProgramData\Initech\Initech.exe.

T1027.013
Encrypted/Encoded File

Rifdoor has encrypted strings with a single byte XOR algorithm.

T1033
System Owner/User Discovery

Rifdoor has the ability to identify the username on the compromised host.

T1082
System Information Discovery

Rifdoor has the ability to identify the Windows version on the compromised host.

T1204.002
Malicious File

Rifdoor has been executed from malicious Excel or Word documents containing macros.

T1547.001
Registry Run Keys / Startup Folder

Rifdoor has created a new registry entry at HKEY_CURRENT_USERS\Software\Microsoft\Windows\CurrentVersion\Run\Graphics with a value of C:\ProgramData\Initech\Initech.exe /run.

T1566.001
Spearphishing Attachment

Rifdoor has been distributed in e-mails with malicious Excel or Word documents.

T1573.001
Symmetric Cryptography

Rifdoor has encrypted command and control (C2) communications with a stream cipher.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Carbon Black HotCroissant April 2020 Open source
    Knight, S.. (2020, April 16). VMware Carbon Black TAU Threat Analysis: The Evolution of Lazarus. Retrieved May 1, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.