Aria-body

S0456

Malware.View on attack.mitre.org

About this malware

Aria-body is a custom backdoor that has been used by Naikon since approximately 2017.

Techniques used24

Procedure examples24

TechniqueProcedure example
T1010
Application Window Discovery

Aria-body has the ability to identify the titles of running windows on a compromised host.

T1016
System Network Configuration Discovery

Aria-body has the ability to identify the location, public IP address, and domain name on a compromised host.

T1025
Data from Removable Media

Aria-body has the ability to collect data from USB devices.

T1027.013
Encrypted/Encoded File

Aria-body has used an encrypted configuration file for its loader.

T1033
System Owner/User Discovery

Aria-body has the ability to identify the username on a compromised host.

T1049
System Network Connections Discovery

Aria-body has the ability to gather TCP and UDP table status listings.

T1055.001
Dynamic-link Library Injection

Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe.

T1057
Process Discovery

Aria-body has the ability to enumerate loaded modules for a process..

T1070.004
File Deletion

Aria-body has the ability to delete files and directories on compromised hosts.

T1071.001
Web Protocols

Aria-body has used HTTP in C2 communications.

T1082
System Information Discovery

Aria-body has the ability to identify the hostname, computer name, Windows version, processor speed, and machine GUID on a compromised host.

T1083
File and Directory Discovery

Aria-body has the ability to gather metadata from a file and to search for file and directory names.

T1090
Proxy

Aria-body has the ability to use a reverse SOCKS proxy module.

T1095
Non-Application Layer Protocol

Aria-body has used TCP in C2 communications.

T1105
Ingress Tool Transfer

Aria-body has the ability to download additional payloads from C2.

View all 24 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. CheckPoint Naikon May 2020 Open source
    CheckPoint. (2020, May 7). Naikon APT: Cyber Espionage Reloaded. Retrieved May 26, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.