Malware.View on attack.mitre.org
Clambling is a modular backdoor written in C++ that has been used by Threat Group-3390 since at least 2017.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Clambling can collect information from a compromised host. |
| T1012 Query Registry |
Clambling has the ability to enumerate Registry keys, including |
| T1016 System Network Configuration Discovery |
Clambling can enumerate the IP address of a compromised machine. |
| T1027 Obfuscated Files or Information |
The Clambling executable has been obfuscated when dropped on a compromised host. |
| T1033 System Owner/User Discovery |
Clambling can identify the username on a compromised host. |
| T1055 Process Injection |
Clambling can inject into the `svchost.exe` process for execution. |
| T1055.012 Process Hollowing |
Clambling can execute binaries through process hollowing. |
| T1056.001 Keylogging |
Clambling can capture keystrokes on a compromised host. |
| T1057 Process Discovery |
Clambling can enumerate processes on a targeted system. |
| T1059.001 PowerShell |
The Clambling dropper can use PowerShell to download the malware. |
| T1059.003 Windows Command Shell |
Clambling can use cmd.exe for command execution. |
| T1071 Application Layer Protocol |
Clambling has the ability to use Telnet for communication. |
| T1071.001 Web Protocols |
Clambling has the ability to communicate over HTTP. |
| T1082 System Information Discovery |
Clambling can discover the hostname, computer name, and Windows version of a targeted machine. |
| T1083 File and Directory Discovery |
Clambling can browse directories on a compromised host. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.