Drovorub

S0502

Malware.View on attack.mitre.org

About this malware

Drovorub is a Linux malware toolset comprised of an agent, client, server, and kernel modules, that has been used by APT28.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1005
Data from Local System

Drovorub can transfer files from the victim machine.

T1014
Rootkit

Drovorub has used a kernel module rootkit to hide processes, files, executables, and network artifacts from user space view.

T1027
Obfuscated Files or Information

Drovorub has used XOR encrypted payloads in WebSocket client to server messages.

T1041
Exfiltration Over C2 Channel

Drovorub can exfiltrate files over C2 infrastructure.

T1059.004
Unix Shell

Drovorub can execute arbitrary commands as root on a compromised system.

T1070.004
File Deletion

Drovorub can delete specific files from a compromised host.

T1071.001
Web Protocols

Drovorub can use the WebSocket protocol and has initiated communication with C2 servers with an HTTP Upgrade request.

T1090.001
Internal Proxy

Drovorub can use a port forwarding rule on its agent module to relay network traffic through the client module to a remote host on the same network.

T1095
Non-Application Layer Protocol

Drovorub can use TCP to communicate between its agent and client modules.

T1105
Ingress Tool Transfer

Drovorub can download files to a compromised host.

T1140
Deobfuscate/Decode Files or Information

Drovorub has de-obsfuscated XOR encrypted payloads in WebSocket messages.

T1547.006
Kernel Modules and Extensions

Drovorub can use kernel modules to establish persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. NSA/FBI Drovorub August 2020 Open source
    NSA/FBI. (2020, August). Russian GRU 85th GTsSS Deploys Previously Undisclosed Drovorub Malware. Retrieved August 25, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.