KOCTOPUS

S0669

Malware.View on attack.mitre.org

About this malware

KOCTOPUS's batch variant is loader used by LazyScripter since 2018 to launch Octopus and Koadic and, in some cases, QuasarRAT. KOCTOPUS also has a VBA variant that has the same functionality as the batch version.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1027.010
Command Obfuscation

KOCTOPUS has obfuscated scripts with the BatchEncryption tool.

T1036.005
Match Legitimate Resource Name or Location

KOCTOPUS has been disguised as legitimate software programs associated with the travel and airline industries.

T1059.001
PowerShell

KOCTOPUS has used PowerShell commands to download additional files.

T1059.003
Windows Command Shell

KOCTOPUS has used `cmd.exe` and batch files for execution.

T1059.005
Visual Basic

KOCTOPUS has used VBScript to call wscript to execute a PowerShell command.

T1070.009
Clear Persistence

KOCTOPUS can delete created registry keys used for persistence as part of its cleanup procedure.

T1082
System Information Discovery

KOCTOPUS has checked the OS version using `wmic.exe` and the `find` command.

T1090
Proxy

KOCTOPUS has deployed a modified version of Invoke-Ngrok to expose open local ports to the Internet.

T1105
Ingress Tool Transfer

KOCTOPUS has executed a PowerShell command to download a file to the system.

T1106
Native API

KOCTOPUS can use the `LoadResource` and `CreateProcessW` APIs for execution.

T1112
Modify Registry

KOCTOPUS has added and deleted keys from the Registry.

T1140
Deobfuscate/Decode Files or Information

KOCTOPUS has deobfuscated itself before executing its commands.

T1204.001
Malicious Link

KOCTOPUS has relied on victims clicking on a malicious link delivered via email.

T1204.002
Malicious File

KOCTOPUS has relied on victims clicking a malicious document for execution.

T1547.001
Registry Run Keys / Startup Folder

KOCTOPUS can set the AutoRun Registry key with a PowerShell command.

View all 20 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. MalwareBytes LazyScripter Feb 2021 Open source
    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.