down_new

S0472

Malware.View on attack.mitre.org

About this malware

down_new is a downloader that has been used by BRONZE BUTLER since at least 2019.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1016
System Network Configuration Discovery

down_new has the ability to identify the MAC address of a compromised host.

T1057
Process Discovery

down_new has the ability to list running processes on a compromised host.

T1071.001
Web Protocols

down_new has the ability to use HTTP in C2 communications.

T1083
File and Directory Discovery

down_new has the ability to list the directories on a compromised host.

T1105
Ingress Tool Transfer

down_new has the ability to download files to the compromised host.

T1132.001
Standard Encoding

down_new has the ability to base64 encode C2 communications.

T1518
Software Discovery

down_new has the ability to gather information on installed applications.

T1518.001
Security Software Discovery

down_new has the ability to detect anti-virus products and processes on a compromised host.

T1573.001
Symmetric Cryptography

down_new has the ability to AES encrypt C2 communications.

T1680
Local Storage Discovery

down_new has the ability to identify the system volume information of a compromised host.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Trend Micro Tick November 2019 Open source
    Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.