ATT&CKSoftwareCSPY Downloader

CSPY Downloader

S0527

Tool.View on attack.mitre.org

About this tool

CSPY Downloader is a tool designed to evade analysis and download additional payloads used by Kimsuky.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1027.002
Software Packing

CSPY Downloader has been packed with UPX.

T1036.004
Masquerade Task or Service

CSPY Downloader has attempted to appear as a legitimate Windows service with a fake description claiming it is used to support packed applications.

T1053.005
Scheduled Task

CSPY Downloader can use the schtasks utility to bypass UAC.

T1070
Indicator Removal

CSPY Downloader has the ability to remove values it writes to the Registry.

T1070.004
File Deletion

CSPY Downloader has the ability to self delete.

T1071.001
Web Protocols

CSPY Downloader can use GET requests to download additional payloads from C2.

T1105
Ingress Tool Transfer

CSPY Downloader can download additional tools to a compromised host.

T1112
Modify Registry

CSPY Downloader can write to the Registry under the %windir% variable to execute tasks.

T1204.002
Malicious File

CSPY Downloader has been delivered via malicious documents with embedded macros.

T1497.001
System Checks

CSPY Downloader can search loaded modules, PEB structure, file paths, Registry keys, and memory to determine if it is being debugged or running in a virtual environment.

T1548.002
Bypass User Account Control

CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges.

T1553.002
Code Signing

CSPY Downloader has come signed with revoked certificates.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cybereason Kimsuky November 2020 Open source
    Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.