BoomBox

S0635

Malware.View on attack.mitre.org

About this malware

BoomBox is a downloader responsible for executing next stage components that has been used by APT29 since at least 2021.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1027
Obfuscated Files or Information

BoomBox can encrypt data using AES prior to exfiltration.

T1033
System Owner/User Discovery

BoomBox can enumerate the username on a compromised host.

T1036
Masquerading

BoomBox has the ability to mask malicious data strings as PDF files.

T1071.001
Web Protocols

BoomBox has used HTTP POST requests for C2.

T1082
System Information Discovery

BoomBox can enumerate the hostname, domain, and IP of a compromised host.

T1083
File and Directory Discovery

BoomBox can search for specific files and directories on a machine.

T1087.002
Domain Account

BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users.

T1087.003
Email Account

BoomBox can execute an LDAP query to discover e-mail accounts for domain users.

T1102
Web Service

BoomBox can download files from Dropbox using a hardcoded access token.

T1105
Ingress Tool Transfer

BoomBox has the ability to download next stage malware components to a compromised system.

T1140
Deobfuscate/Decode Files or Information

BoomBox can decrypt AES-encrypted files downloaded from C2.

T1204.002
Malicious File

BoomBox has gained execution through user interaction with a malicious file.

T1218.011
Rundll32

BoomBox can use RunDLL32 for execution.

T1480
Execution Guardrails

BoomBox can check its current working directory and for the presence of a specific file and terminate if specific values are not found.

T1547.001
Registry Run Keys / Startup Folder

BoomBox can establish persistence by writing the Registry value MicroNativeCacheSvc to HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

View all 16 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. MSTIC Nobelium Toolset May 2021 Open source
    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.