ATT&CKSoftwareRising Sun

Rising Sun

S0448

Malware.View on attack.mitre.org

About this malware

Rising Sun is a modular backdoor that was used extensively in Operation Sharpshooter between 2017 and 2019. Rising Sun infected at least 87 organizations around the world, including nuclear, defense, energy, and financial service companies. Security researchers assessed Rising Sun included some source code from Lazarus Group's Trojan Duuzer.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1005
Data from Local System

Rising Sun has collected data and files from a compromised host.

T1012
Query Registry

Rising Sun has identified the OS product name from a compromised host by searching the registry for `SOFTWARE\MICROSOFT\Windows NT\ CurrentVersion | ProductName`.

T1016
System Network Configuration Discovery

Rising Sun can detect network adapter and IP address information.

T1016.001
Internet Connection Discovery

Rising Sun can test a connection to a specified network IP address over a specified port number.

T1027.013
Encrypted/Encoded File

Configuration data used by Rising Sun has been encrypted using an RC4 stream algorithm.

T1033
System Owner/User Discovery

Rising Sun can detect the username of the infected host.

T1041
Exfiltration Over C2 Channel

Rising Sun can send data gathered from the infected machine via HTTP POST request to the C2.

T1057
Process Discovery

Rising Sun can enumerate all running processes and process information on an infected machine.

T1059.003
Windows Command Shell

Rising Sun has executed commands using `cmd.exe /c “<command> > <%temp%>\AM<random>. tmp” 2>&1`.

T1070
Indicator Removal

Rising Sun can clear a memory blog in the process by overwriting it with junk bytes.

T1070.004
File Deletion

Rising Sun can delete files and artifacts it creates.

T1071.001
Web Protocols

Rising Sun has used HTTP and HTTPS for command and control.

T1082
System Information Discovery

Rising Sun can detect the computer name and operating system.

T1083
File and Directory Discovery

Rising Sun can enumerate information about files from the infected system, including file size, attributes, creation time, last access time, and write time. Rising Sun can enumerate the compilation timestamp of Windows executable files.

T1106
Native API

Rising Sun used dynamic API resolutions to various Windows APIs by leveraging `LoadLibrary()` and `GetProcAddress()`.

View all 20 procedure examples

Groups that use it0

None recorded.

Campaigns1

References1

  1. McAfee Sharpshooter December 2018 Open source
    Sherstobitoff, R., Malhotra, A., et. al.. (2018, December 18). Operation Sharpshooter Campaign Targets Global Defense, Critical Infrastructure. Retrieved May 14, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.