BBK

S0470

Malware.View on attack.mitre.org

About this malware

BBK is a downloader that has been used by BRONZE BUTLER since at least 2019.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1027.003
Steganography

BBK can extract a malicious Portable Executable (PE) from a photo.

T1055
Process Injection

BBK has the ability to inject shellcode into svchost.exe.

T1059.003
Windows Command Shell

BBK has the ability to use cmd to run a Portable Executable (PE) on the compromised host.

T1071.001
Web Protocols

BBK has the ability to use HTTP in communications with C2.

T1105
Ingress Tool Transfer

BBK has the ability to download files from C2 to the infected host.

T1106
Native API

BBK has the ability to use the CreatePipe API to add a sub-process for execution via cmd.

T1140
Deobfuscate/Decode Files or Information

BBK has the ability to decrypt AES encrypted payloads.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Trend Micro Tick November 2019 Open source
    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.