Malware.View on attack.mitre.org
GrimAgent is a backdoor that has been used before the deployment of Ryuk ransomware since at least 2020; it is likely used by FIN6 and Wizard Spider.
| Technique | Procedure example |
|---|---|
| T1001.001 Junk Data |
GrimAgent can pad C2 messages with random generated values. |
| T1005 Data from Local System |
GrimAgent can collect data and files from a compromised host. |
| T1016 System Network Configuration Discovery |
GrimAgent can enumerate the IP and domain of a target system. |
| T1027 Obfuscated Files or Information |
GrimAgent has used Rotate on Right (RoR) and Rotate on Left (RoL) functionality to encrypt strings. |
| T1027.001 Binary Padding |
GrimAgent has the ability to add bytes to change the file hash. |
| T1033 System Owner/User Discovery |
GrimAgent can identify the user id on a target machine. |
| T1041 Exfiltration Over C2 Channel |
GrimAgent has sent data related to a compromise host over its C2 channel. |
| T1053.005 Scheduled Task |
GrimAgent has the ability to set persistence using the Task Scheduler. |
| T1059.003 Windows Command Shell |
GrimAgent can use the Windows Command Shell to execute commands, including its own removal. |
| T1070.004 File Deletion |
GrimAgent can delete old binaries on a compromised host. |
| T1070.009 Clear Persistence |
GrimAgent can delete previously created tasks on a compromised host. |
| T1071.001 Web Protocols |
GrimAgent has the ability to use HTTP for C2 communications. |
| T1082 System Information Discovery |
GrimAgent can collect the OS, and build version on a compromised host. |
| T1083 File and Directory Discovery |
GrimAgent has the ability to enumerate files and directories on a compromised host. |
| T1105 Ingress Tool Transfer |
GrimAgent has the ability to download and execute additional payloads. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.