BLUELIGHT

S0657

Malware.View on attack.mitre.org

About this malware

BLUELIGHT is a remote access Trojan used by APT37 that was first observed in early 2021.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1016
System Network Configuration Discovery

BLUELIGHT can collect IP information from the victim’s machine.

T1027.013
Encrypted/Encoded File

BLUELIGHT has a XOR-encoded payload.

T1033
System Owner/User Discovery

BLUELIGHT can collect the username on a compromised host.

T1041
Exfiltration Over C2 Channel

BLUELIGHT has exfiltrated data over its C2 channel.

T1057
Process Discovery

BLUELIGHT can collect process filenames and SID authority level.

T1070.004
File Deletion

BLUELIGHT can uninstall itself.

T1071.001
Web Protocols

BLUELIGHT can use HTTP/S for C2 using the Microsoft Graph API.

T1082
System Information Discovery

BLUELIGHT has collected the computer name and OS version from victim machines.

T1083
File and Directory Discovery

BLUELIGHT can enumerate files and collect associated metadata.

T1102.002
Bidirectional Communication

BLUELIGHT can use different cloud providers for its C2.

T1105
Ingress Tool Transfer

BLUELIGHT can download additional files onto the host.

T1113
Screen Capture

BLUELIGHT has captured a screenshot of the display every 30 seconds for the first 5 minutes after initiating a C2 loop, and then once every five minutes thereafter.

T1124
System Time Discovery

BLUELIGHT can collect the local time on a compromised host.

T1497.001
System Checks

BLUELIGHT can check to see if the infected machine has VM tools running.

T1518.001
Security Software Discovery

BLUELIGHT can collect a list of anti-virus products installed on a machine.

View all 19 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Volexity InkySquid BLUELIGHT August 2021 Open source
    Cash, D., Grunzweig, J., Meltzer, M., Adair, S., Lancaster, T. (2021, August 17). North Korean APT InkySquid Infects Victims Using Browser Exploits. Retrieved September 30, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.