GrimAgent

S0632

Malware.View on attack.mitre.org

About this malware

GrimAgent is a backdoor that has been used before the deployment of Ryuk ransomware since at least 2020; it is likely used by FIN6 and Wizard Spider.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1001.001
Junk Data

GrimAgent can pad C2 messages with random generated values.

T1005
Data from Local System

GrimAgent can collect data and files from a compromised host.

T1016
System Network Configuration Discovery

GrimAgent can enumerate the IP and domain of a target system.

T1027
Obfuscated Files or Information

GrimAgent has used Rotate on Right (RoR) and Rotate on Left (RoL) functionality to encrypt strings.

T1027.001
Binary Padding

GrimAgent has the ability to add bytes to change the file hash.

T1033
System Owner/User Discovery

GrimAgent can identify the user id on a target machine.

T1041
Exfiltration Over C2 Channel

GrimAgent has sent data related to a compromise host over its C2 channel.

T1053.005
Scheduled Task

GrimAgent has the ability to set persistence using the Task Scheduler.

T1059.003
Windows Command Shell

GrimAgent can use the Windows Command Shell to execute commands, including its own removal.

T1070.004
File Deletion

GrimAgent can delete old binaries on a compromised host.

T1070.009
Clear Persistence

GrimAgent can delete previously created tasks on a compromised host.

T1071.001
Web Protocols

GrimAgent has the ability to use HTTP for C2 communications.

T1082
System Information Discovery

GrimAgent can collect the OS, and build version on a compromised host.

T1083
File and Directory Discovery

GrimAgent has the ability to enumerate files and directories on a compromised host.

T1105
Ingress Tool Transfer

GrimAgent has the ability to download and execute additional payloads.

View all 25 procedure examples

Groups that use it2

Campaigns0

None recorded.

References1

  1. Group IB GrimAgent July 2021 Open source
    Priego, A. (2021, July). THE BROTHERS GRIM: THE REVERSING TALE OF GRIMAGENT MALWARE USED BY RYUK. Retrieved September 19, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.