ATT&CKSoftwareBackConfig

BackConfig

S0475

Malware.View on attack.mitre.org

About this malware

BackConfig is a custom Trojan with a flexible plugin architecture that has been used by Patchwork.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1027.010
Command Obfuscation

BackConfig has used compressed and decimal encoded VBS scripts.

T1036.005
Match Legitimate Resource Name or Location

BackConfig has hidden malicious payloads in %USERPROFILE%\Adobe\Driver\dwg\ and mimicked the legitimate DHCP service binary.

T1053.005
Scheduled Task

BackConfig has the ability to use scheduled tasks to repeatedly execute malicious payloads on a compromised host.

T1059.003
Windows Command Shell

BackConfig can download and run batch files to execute commands on a compromised host.

T1059.005
Visual Basic

BackConfig has used VBS to install its downloader component and malicious documents with VBA macro code.

T1070.004
File Deletion

BackConfig has the ability to remove files and folders related to previous infections.

T1071.001
Web Protocols

BackConfig has the ability to use HTTPS for C2 communiations.

T1082
System Information Discovery

BackConfig has the ability to gather the victim's computer name.

T1083
File and Directory Discovery

BackConfig has the ability to identify folders and files related to previous infections.

T1105
Ingress Tool Transfer

BackConfig can download and execute additional payloads on a compromised host.

T1106
Native API

BackConfig can leverage API functions such as ShellExecuteA and HttpOpenRequestA in the process of downloading and executing files.

T1137.001
Office Template Macros

BackConfig has the ability to use hidden columns in Excel spreadsheets to store executable files or commands for VBA macros.

T1140
Deobfuscate/Decode Files or Information

BackConfig has used a custom routine to decrypt strings.

T1204.001
Malicious Link

BackConfig has compromised victims via links to URLs hosting malicious content.

T1553.002
Code Signing

BackConfig has been signed with self signed digital certificates mimicking a legitimate software company.

View all 16 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit 42 BackConfig May 2020 Open source
    Hinchliffe, A. and Falcone, R. (2020, May 11). Updated BackConfig Malware Targeting Government and Military Organizations in South Asia. Retrieved June 17, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.