Malware.View on attack.mitre.org
RCSession is a backdoor written in C++ that has been in use since at least 2018 by Mustang Panda and by Threat Group-3390 (Type II Backdoor).
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
RCSession can collect data from a compromised host. |
| T1027.011 Fileless Storage |
RCSession can store its obfuscated configuration file in the Registry under `HKLM\SOFTWARE\Plus` or `HKCU\SOFTWARE\Plus`. |
| T1027.015 Compression |
RCSession can compress and obfuscate its strings to evade detection on a compromised host. |
| T1033 System Owner/User Discovery |
RCSession can gather system owner information, including user and administrator privileges. |
| T1036 Masquerading |
RCSession has used a file named English.rtf to appear benign on victim hosts. |
| T1055.012 Process Hollowing |
RCSession can launch itself from a hollowed svchost.exe process. |
| T1056.001 Keylogging |
RCSession has the ability to capture keystrokes on a compromised host. |
| T1057 Process Discovery |
RCSession can identify processes based on PID. |
| T1059.003 Windows Command Shell |
RCSession can use `cmd.exe` for execution on compromised hosts. |
| T1070.004 File Deletion |
RCSession can remove files from a targeted system. |
| T1071.001 Web Protocols |
RCSession can use HTTP in C2 communications. |
| T1082 System Information Discovery |
RCSession can gather system information from a compromised host. |
| T1095 Non-Application Layer Protocol |
RCSession has the ability to use TCP and UDP in C2 communications. |
| T1105 Ingress Tool Transfer |
RCSession has the ability to drop additional files to an infected machine. |
| T1106 Native API |
RCSession can use WinSock API for communication including |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.