ATT&CKSoftwareShimRatReporter

ShimRatReporter

S0445

Tool.View on attack.mitre.org

About this tool

ShimRatReporter is a tool used by suspected Chinese adversary Mofang to automatically conduct initial discovery. The details from this discovery are used to customize follow-on payloads (such as ShimRat) as well as set up faux infrastructure which mimics the adversary's targets. ShimRatReporter has been used in campaigns targeting multiple countries and sectors including government, military, critical infrastructure, automobile, and weapons development.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1016
System Network Configuration Discovery

ShimRatReporter gathered the local proxy, domain, IP, routing tables, mac address, gateway, DNS servers, and DHCP status information from an infected host.

T1020
Automated Exfiltration

ShimRatReporter sent collected system and network information compiled into a report to an adversary-controlled C2.

T1027
Obfuscated Files or Information

ShimRatReporter encrypted gathered information with a combination of shifting and XOR using a static key.

T1036.005
Match Legitimate Resource Name or Location

ShimRatReporter spoofed itself as AlphaZawgyl_font.exe, a specialized Unicode font.

T1041
Exfiltration Over C2 Channel

ShimRatReporter sent generated reports to the C2 via HTTP POST requests.

T1049
System Network Connections Discovery

ShimRatReporter used the Windows function GetExtendedUdpTable to detect connected UDP endpoints.

T1057
Process Discovery

ShimRatReporter listed all running processes on the machine.

T1069
Permission Groups Discovery

ShimRatReporter gathered the local privileges for the infected host.

T1071.001
Web Protocols

ShimRatReporter communicated over HTTP with preconfigured C2 servers.

T1082
System Information Discovery

ShimRatReporter gathered the operating system name and specific Windows version of an infected machine.

T1087
Account Discovery

ShimRatReporter listed all non-privileged and privileged accounts available on the machine.

T1105
Ingress Tool Transfer

ShimRatReporter had the ability to download additional payloads.

T1106
Native API

ShimRatReporter used several Windows API functions to gather information from the infected system.

T1119
Automated Collection

ShimRatReporter gathered information automatically, without instruction from a C2, related to the user and host machine that is compiled into a report and sent to the operators.

T1518
Software Discovery

ShimRatReporter gathered a list of installed software on the infected host.

View all 16 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. FOX-IT May 2016 Mofang Open source
    Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.