VaporRage

S0636

Malware.View on attack.mitre.org

About this malware

VaporRage is a shellcode downloader that has been used by APT29 since at least 2021.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1071.001
Web Protocols

VaporRage can use HTTP to download shellcode from compromised websites.

T1105
Ingress Tool Transfer

VaporRage has the ability to download malicious shellcode to compromised systems.

T1140
Deobfuscate/Decode Files or Information

VaporRage can deobfuscate XOR-encoded shellcode prior to execution.

T1480
Execution Guardrails

VaporRage has the ability to check for the presence of a specific DLL and terminate if it is not found.

Groups that use it1

Campaigns0

None recorded.

References1

  1. MSTIC Nobelium Toolset May 2021 Open source
    MSTIC. (2021, May 28). Breaking down NOBELIUM’s latest early-stage toolset. Retrieved August 4, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.