WellMess

S0514

Malware.View on attack.mitre.org

About this malware

WellMess is lightweight malware family with variants written in .NET and Golang that has been in use since at least 2018 by APT29.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1001.001
Junk Data

WellMess can use junk data in the Base64 string for additional obfuscation.

T1005
Data from Local System

WellMess can send files from the victim machine to C2.

T1016
System Network Configuration Discovery

WellMess can identify the IP address and user domain on the target machine.

T1033
System Owner/User Discovery

WellMess can collect the username on the victim machine to send to C2.

T1059.001
PowerShell

WellMess can execute PowerShell scripts received from C2.

T1059.003
Windows Command Shell

WellMess can execute command line scripts received from C2.

T1069.002
Domain Groups

WellMess can identify domain group membership for the current user.

T1071.001
Web Protocols

WellMess can use HTTP and HTTPS in C2 communications.

T1071.004
DNS

WellMess has the ability to use DNS tunneling for C2 communications.

T1082
System Information Discovery

WellMess can identify the computer name of a compromised host.

T1105
Ingress Tool Transfer

WellMess can write files to a compromised host.

T1132.001
Standard Encoding

WellMess has used Base64 encoding to uniquely identify communication to and from the C2.

T1140
Deobfuscate/Decode Files or Information

WellMess can decode and decrypt data received from C2.

T1573.001
Symmetric Cryptography

WellMess can encrypt HTTP POST data using RC6 and a dynamically generated AES key encrypted with a hard coded RSA public key.

T1573.002
Asymmetric Cryptography

WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates.

Groups that use it1

Campaigns0

None recorded.

References3

  1. CISA WellMess July 2020 Open source
    CISA. (2020, July 16). MAR-10296782-2.v1 – WELLMESS. Retrieved September 24, 2020.
  2. NCSC APT29 July 2020 Open source
    National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020.
  3. PWC WellMess July 2020 Open source
    PWC. (2020, July 16). How WellMess malware has been used to target COVID-19 vaccines. Retrieved September 24, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.