DropBook

S0547

Malware.View on attack.mitre.org

About this malware

DropBook is a Python-based backdoor compiled with PyInstaller.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1059.003
Windows Command Shell

DropBook can execute arbitrary shell commands on the victims' machines.

T1059.006
Python

DropBook is a Python-based backdoor compiled with PyInstaller.

T1082
System Information Discovery

DropBook has checked for the presence of Arabic language in the infected machine's settings.

T1083
File and Directory Discovery

DropBook can collect the names of all files and folders in the Program Files directories.

T1102
Web Service

DropBook can communicate with its operators by exploiting the Simplenote, DropBox, and the social media platform, Facebook, where it can create fake accounts to control the backdoor and receive instructions.

T1105
Ingress Tool Transfer

DropBook can download and execute additional files.

T1140
Deobfuscate/Decode Files or Information

DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules.

T1567
Exfiltration Over Web Service

DropBook has used legitimate web services to exfiltrate data.

T1614.001
System Language Discovery

DropBook has checked for the presence of Arabic language in the infected machine's settings.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cybereason Molerats Dec 2020 Open source
    Cybereason Nocturnus Team. (2020, December 9). MOLERATS IN THE CLOUD: New Malware Arsenal Abuses Cloud Platforms in Middle East Espionage Campaign. Retrieved December 22, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.