ATT&CKSoftwareMechaFlounder

MechaFlounder

S0459

Malware.View on attack.mitre.org

About this malware

MechaFlounder is a python-based remote access tool (RAT) that has been used by APT39. The payload uses a combination of actor developed code and code snippets freely available online in development communities.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1033
System Owner/User Discovery

MechaFlounder has the ability to identify the username and hostname on a compromised host.

T1036.005
Match Legitimate Resource Name or Location

MechaFlounder has been downloaded as a file named lsass.exe, which matches the legitimate Windows file.

T1041
Exfiltration Over C2 Channel

MechaFlounder has the ability to send the compromised user's account name and hostname within a URL to C2.

T1059.003
Windows Command Shell

MechaFlounder has the ability to run commands on a compromised host.

T1059.006
Python

MechaFlounder uses a python-based payload.

T1071.001
Web Protocols

MechaFlounder has the ability to use HTTP in communication with C2.

T1105
Ingress Tool Transfer

MechaFlounder has the ability to upload and download files to and from a compromised host.

T1132.001
Standard Encoding

MechaFlounder has the ability to use base16 encoded strings in C2.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit 42 MechaFlounder March 2019 Open source
    Falcone, R. (2019, March 4). New Python-Based Payload MechaFlounder Used by Chafer. Retrieved May 27, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.