ATT&CKSoftwareObliqueRAT

ObliqueRAT

S0644

Malware.View on attack.mitre.org

About this malware

ObliqueRAT is a remote access trojan, similar to Crimson, that has been in use by Transparent Tribe since at least 2020.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1025
Data from Removable Media

ObliqueRAT has the ability to extract data from removable devices connected to the endpoint.

T1027.003
Steganography

ObliqueRAT can hide its payload in BMP images hosted on compromised websites.

T1030
Data Transfer Size Limits

ObliqueRAT can break large files of interest into smaller chunks to prepare them for exfiltration.

T1033
System Owner/User Discovery

ObliqueRAT can check for blocklisted usernames on infected endpoints.

T1057
Process Discovery

ObliqueRAT can check for blocklisted process names on a compromised host.

T1074.001
Local Data Staging

ObliqueRAT can copy specific files, webcam captures, and screenshots to local directories.

T1082
System Information Discovery

ObliqueRAT has the ability to check for blocklisted computer names on infected endpoints.

T1083
File and Directory Discovery

ObliqueRAT has the ability to recursively enumerate files on an infected endpoint.

T1113
Screen Capture

ObliqueRAT can capture a screenshot of the current screen.

T1120
Peripheral Device Discovery

ObliqueRAT can discover pluggable/removable drives to extract files from.

T1125
Video Capture

ObliqueRAT can capture images from webcams on compromised hosts.

T1204.001
Malicious Link

ObliqueRAT has gained execution on targeted systems through luring users to click on links to malicious URLs.

T1497.001
System Checks

ObliqueRAT can halt execution if it identifies processes belonging to virtual machine software or analysis tools.

T1547.001
Registry Run Keys / Startup Folder

ObliqueRAT can gain persistence by a creating a shortcut in the infected user's Startup directory.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Talos Oblique RAT March 2021 Open source
    Malhotra, A. (2021, March 2). ObliqueRAT returns with new campaign using hijacked websites. Retrieved September 2, 2021.
  2. Talos Transparent Tribe May 2021 Open source
    Malhotra, A. et al. (2021, May 13). Transparent Tribe APT expands its Windows malware arsenal. Retrieved September 2, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.