Lucifer

S0532

Malware.View on attack.mitre.org

About this malware

Lucifer is a crypto miner and DDoS hybrid malware that leverages well-known exploits to spread laterally on Windows platforms.

Techniques used24

Procedure examples24

TechniqueProcedure example
T1012
Query Registry

Lucifer can check for existing stratum cryptomining information in HKLM\Software\Microsoft\Windows\CurrentVersion\spreadCpuXmr – %stratum info%.

T1016
System Network Configuration Discovery

Lucifer can collect the IP address of a compromised host.

T1021.002
SMB/Windows Admin Shares

Lucifer can infect victims by brute forcing SMB.

T1027.002
Software Packing

Lucifer has used UPX packed binaries.

T1033
System Owner/User Discovery

Lucifer has the ability to identify the username on a compromised host.

T1046
Network Service Discovery

Lucifer can scan for open ports including TCP ports 135 and 1433.

T1047
Windows Management Instrumentation

Lucifer can use WMI to log into remote machines for propagation.

T1049
System Network Connections Discovery

Lucifer can identify the IP and port numbers for all remote connections from the compromised host.

T1053.005
Scheduled Task

Lucifer has established persistence by creating the following scheduled task schtasks /create /sc minute /mo 1 /tn QQMusic ^ /tr C:Users\%USERPROFILE%\Downloads\spread.exe /F.

T1057
Process Discovery

Lucifer can identify the process that owns remote connections.

T1059.003
Windows Command Shell

Lucifer can issue shell commands to download and execute additional payloads.

T1071
Application Layer Protocol

Lucifer can use the Stratum protocol on port 10001 for communication between the cryptojacking bot and the mining server.

T1082
System Information Discovery

Lucifer can collect the computer name, system architecture, default language, and processor frequency of a compromised host.

T1105
Ingress Tool Transfer

Lucifer can download and execute a replica of itself using certutil.

T1110.001
Password Guessing

Lucifer has attempted to brute force TCP ports 135 (RPC) and 1433 (MSSQL) with the default username or list of usernames and passwords.

View all 24 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Unit 42 Lucifer June 2020 Open source
    Hsu, K. et al. (2020, June 24). Lucifer: New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices. Retrieved November 16, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.