Okrum

S0439

Malware.View on attack.mitre.org

About this malware

Okrum is a Windows backdoor that has been seen in use since December 2016 with strong links to Ke3chang.

Techniques used34

Procedure examples34

TechniqueProcedure example
T1001
Data Obfuscation

Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests.

T1001.003
Protocol or Service Impersonation

Okrum leverages the HTTP protocol for C2 communication, while hiding the actual messages in the Cookie and Set-Cookie headers of the HTTP requests.

T1003.001
LSASS Memory

Okrum was seen using MimikatzLite to perform credential dumping.

T1003.005
Cached Domain Credentials

Okrum was seen using modified Quarks PwDump to perform credential dumping.

T1016
System Network Configuration Discovery

Okrum can collect network information, including the host IP address, DNS, and proxy information.

T1027.003
Steganography

Okrum's payload is encrypted and embedded within its loader, or within a legitimate PNG file.

T1033
System Owner/User Discovery

Okrum can collect the victim username.

T1036.004
Masquerade Task or Service

Okrum can establish persistence by adding a new service NtmsSvc with the display name Removable Storage to masquerade as a legitimate Removable Storage Manager.

T1041
Exfiltration Over C2 Channel

Data exfiltration is done by Okrum using the already opened channel with the C2 server.

T1049
System Network Connections Discovery

Okrum was seen using NetSess to discover NetBIOS sessions.

T1053.005
Scheduled Task

Okrum's installer can attempt to achieve persistence by creating a scheduled task.

T1056.001
Keylogging

Okrum was seen using a keylogger tool to capture keystrokes.

T1059.003
Windows Command Shell

Okrum's backdoor has used cmd.exe to execute arbitrary commands as well as batch scripts to update itself to a newer version.

T1070.004
File Deletion

Okrum's backdoor deletes files after they have been successfully uploaded to C2 servers.

T1071.001
Web Protocols

Okrum uses HTTP for communication with its C2.

View all 34 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET Okrum July 2019 Open source
    Hromcova, Z. (2019, July). OKRUM AND KETRICAN: AN OVERVIEW OF RECENT KE3CHANG GROUP ACTIVITY. Retrieved May 6, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.