ATT&CKSoftwareSLOTHFULMEDIA

SLOTHFULMEDIA

S0533

Malware.View on attack.mitre.org

About this malware

SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least January 2017. It has been used to target government organizations, defense contractors, universities, and energy companies in Russia, India, Kazakhstan, Kyrgyzstan, Malaysia, Ukraine, and Eastern Europe.

In October 2020, Kaspersky Labs assessed SLOTHFULMEDIA is part of an activity cluster it refers to as "IAmTheKing". ESET also noted code similarity between SLOTHFULMEDIA and droppers used by a group it refers to as "PowerPool".

Techniques used24

Procedure examples24

TechniqueProcedure example
T1001
Data Obfuscation

SLOTHFULMEDIA has hashed a string containing system information prior to exfiltration via POST requests.

T1005
Data from Local System

SLOTHFULMEDIA has uploaded files and information from victim machines.

T1007
System Service Discovery

SLOTHFULMEDIA has the capability to enumerate services.

T1033
System Owner/User Discovery

SLOTHFULMEDIA has collected the username from a victim machine.

T1036.004
Masquerade Task or Service

SLOTHFULMEDIA has named a service it establishes on victim machines as "TaskFrame" to hide its malicious purpose.

T1036.005
Match Legitimate Resource Name or Location

SLOTHFULMEDIA has mimicked the names of known executables, such as mediaplayer.exe.

T1041
Exfiltration Over C2 Channel

SLOTHFULMEDIA has sent system information to a C2 server via HTTP and HTTPS POST requests.

T1049
System Network Connections Discovery

SLOTHFULMEDIA can enumerate open ports on a victim machine.

T1055
Process Injection

SLOTHFULMEDIA can inject into running processes on a compromised host.

T1056.001
Keylogging

SLOTHFULMEDIA has a keylogging capability.

T1057
Process Discovery

SLOTHFULMEDIA has enumerated processes by ID, name, or privileges.

T1059.003
Windows Command Shell

SLOTHFULMEDIA can open a command line to execute commands.

T1070.004
File Deletion

SLOTHFULMEDIA has deleted itself and the 'index.dat' file on a compromised machine to remove recent Internet history from the system.

T1071.001
Web Protocols

SLOTHFULMEDIA has used HTTP and HTTPS for C2 communications.

T1082
System Information Discovery

SLOTHFULMEDIA has collected system name, OS version, adapter information, and memory usage from a victim machine.

View all 24 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References5

  1. CISA MAR SLOTHFULMEDIA October 2020 Open source
    DHS/CISA, Cyber National Mission Force. (2020, October 1). Malware Analysis Report (MAR) MAR-10303705-1.v1 – Remote Access Trojan: SLOTHFULMEDIA. Retrieved October 2, 2020.
  2. Costin Raiu IAmTheKing October 2020 Open source
    Costin Raiu. (2020, October 2). Costin Raiu Twitter IAmTheKing SlothfulMedia. Retrieved September 12, 2024.
  3. ESET PowerPool Code October 2020 Open source
    ESET Research. (2020, October 1). ESET Research Tweet Linking Slothfulmedia and PowerPool. Retrieved September 12, 2024.
  4. Kaspersky IAmTheKing October 2020 Open source
    Ivan Kwiatkowski, Pierre Delcher, Felix Aime. (2020, October 15). IAmTheKing and the SlothfulMedia malware family. Retrieved October 15, 2020.
  5. USCYBERCOM SLOTHFULMEDIA October 2020 Open source
    USCYBERCOM. (2020, October 1). USCYBERCOM Cybersecurity Alert SLOTHFULMEDIA. Retrieved September 12, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.