KGH_SPY

S0526

Malware.View on attack.mitre.org

About this malware

KGH_SPY is a modular suite of tools used by Kimsuky for reconnaissance, information stealing, and backdoor capabilities. KGH_SPY derived its name from PDB paths and internal names found in samples containing "KGH".

Techniques used20

Procedure examples20

TechniqueProcedure example
T1005
Data from Local System

KGH_SPY can send a file containing victim system information to C2.

T1027.013
Encrypted/Encoded File

KGH_SPY has used encrypted strings in its installer.

T1036.005
Match Legitimate Resource Name or Location

KGH_SPY has masqueraded as a legitimate Windows tool.

T1037.001
Logon Script (Windows)

KGH_SPY has the ability to set the HKCU\Environment\UserInitMprLogonScript Registry key to execute logon scripts.

T1041
Exfiltration Over C2 Channel

KGH_SPY can exfiltrate collected information from the host to the C2 server.

T1056.001
Keylogging

KGH_SPY can perform keylogging by polling the GetAsyncKeyState() function.

T1059.001
PowerShell

KGH_SPY can execute PowerShell commands on the victim's machine.

T1059.003
Windows Command Shell

KGH_SPY has the ability to set a Registry key to run a cmd.exe command.

T1071.001
Web Protocols

KGH_SPY can send data to C2 with HTTP POST requests.

T1074.001
Local Data Staging

KGH_SPY can save collected system information to a file named "info" before exfiltration.

T1083
File and Directory Discovery

KGH_SPY can enumerate files and directories on a compromised host.

T1105
Ingress Tool Transfer

KGH_SPY has the ability to download and execute code from remote servers.

T1114.001
Local Email Collection

KGH_SPY can harvest data from mail clients.

T1140
Deobfuscate/Decode Files or Information

KGH_SPY can decrypt encrypted strings and write them to a newly created folder.

T1204.002
Malicious File

KGH_SPY has been spread through Word documents containing malicious macros.

View all 20 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cybereason Kimsuky November 2020 Open source
    Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.