SysUpdate

S0663

Malware.View on attack.mitre.org

About this malware

SysUpdate is a backdoor written in C++ that has been used by Threat Group-3390 since at least 2020.

Techniques used31

Procedure examples31

TechniqueProcedure example
T1005
Data from Local System

SysUpdate can collect information and files from a compromised host.

T1007
System Service Discovery

SysUpdate can collect a list of services on a victim machine.

T1016
System Network Configuration Discovery

SysUpdate can collected the IP address and domain name of a compromised host.

T1016.001
Internet Connection Discovery

SysUpdate can contact the DNS server operated by Google as part of its C2 establishment process.

T1027.002
Software Packing

SysUpdate has been packed with VMProtect.

T1027.011
Fileless Storage

SysUpdate can store its encoded configuration file within Software\Classes\scConfig in either HKEY_LOCAL_MACHINE or HKEY_CURRENT_USER.

T1027.013
Encrypted/Encoded File

SysUpdate can encrypt and encode its configuration file.

T1033
System Owner/User Discovery

SysUpdate can collect the username from a compromised host.

T1036.004
Masquerade Task or Service

SysUpdate has named their unit configuration file similarly to other unit files residing in the same directory, `/usr/lib/systemd/system/`, to appear benign.

T1041
Exfiltration Over C2 Channel

SysUpdate has exfiltrated data over its C2 channel.

T1047
Windows Management Instrumentation

SysUpdate can use WMI for execution on a compromised host.

T1057
Process Discovery

SysUpdate can collect information about running processes.

T1070.004
File Deletion

SysUpdate can delete its configuration file from the targeted system.

T1071.004
DNS

SysUpdate has used DNS TXT requests as for its C2 communication.

T1082
System Information Discovery

SysUpdate can collect a system's architecture, operating system version, and hostname.

View all 31 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Trend Micro Iron Tiger April 2021 Open source
    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.