Kivars

S0437

Malware.View on attack.mitre.org

About this malware

Kivars is a modular remote access tool (RAT), derived from the Bifrost RAT, that was used by BlackTech in a 2010 campaign.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1021
Remote Services

Kivars has the ability to remotely trigger keyboard input and mouse clicks.

T1056.001
Keylogging

Kivars has the ability to initiate keylogging on the infected host.

T1070.004
File Deletion

Kivars has the ability to uninstall malware from the infected host.

T1083
File and Directory Discovery

Kivars has the ability to list drives on the infected host.

T1105
Ingress Tool Transfer

Kivars has the ability to download and execute files.

T1113
Screen Capture

Kivars has the ability to capture screenshots on the infected host.

T1564.003
Hidden Window

Kivars has the ability to conceal its activity through hiding active windows.

Groups that use it1

Campaigns0

None recorded.

References1

  1. TrendMicro BlackTech June 2017 Open source
    Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.