BendyBear

S0574

Malware.View on attack.mitre.org

About this malware

BendyBear is an x64 shellcode for a stage-zero implant designed to download malware from a C2 server. First discovered in August 2020, BendyBear shares a variety of features with Waterbear, malware previously attributed to the Chinese cyber espionage group BlackTech.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1001.001
Junk Data

BendyBear has used byte randomization to obscure its behavior.

T1012
Query Registry

BendyBear can query the host's Registry key at HKEY_CURRENT_USER\Console\QuickEdit to retrieve data.

T1027.013
Encrypted/Encoded File

BendyBear has encrypted payloads using RC4 and XOR.

T1027.014
Polymorphic Code

BendyBear changes its runtime footprint during code execution to evade signature-based defenses.

T1105
Ingress Tool Transfer

BendyBear is designed to download an implant from a C2 server.

T1106
Native API

BendyBear can load and execute modules and Windows Application Programming (API) calls using standard shellcode API hashing.

T1124
System Time Discovery

BendyBear has the ability to determine local time on a compromised host.

T1140
Deobfuscate/Decode Files or Information

BendyBear has decrypted function blocks using a XOR key during runtime to evade detection.

T1497.003
Time Based Checks

BendyBear can check for analysis environments and signs of debugging using the Windows API kernel32!GetTickCountKernel32 call.

T1571
Non-Standard Port

BendyBear has used a custom RC4 and XOR encrypted protocol over port 443 for C2.

T1573.001
Symmetric Cryptography

BendyBear communicates to a C2 server over port 443 using modified RC4 and XOR-encrypted chunks.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Unit42 BendyBear Feb 2021 Open source
    Harbison, M. (2021, February 9). BendyBear: Novel Chinese Shellcode Linked With Cyber Espionage Group BlackTech. Retrieved February 16, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.