Lizar

S0681

Malware.View on attack.mitre.org

About this malware

Lizar is a modular remote access tool written using the .NET Framework that shares structural similarities to Carbanak. It has likely been used by FIN7 since at least February 2021.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1003.001
LSASS Memory

Lizar can run Mimikatz to harvest credentials.

T1016
System Network Configuration Discovery

Lizar has retrieved network information from a compromised host, such as the MAC address.

T1027
Obfuscated Files or Information

Lizar has obfuscated the fingerprint of the victim system, the local IP address, and the Fowler-Noll-V 1 (FNV-1) hash of the local IP address using an XOR operation. The data is then sent to the C2 server.

T1033
System Owner/User Discovery

Lizar can collect the username from the system.

T1049
System Network Connections Discovery

Lizar has a plugin to retrieve information about all active network sessions on the infected server.

T1055
Process Injection

Lizar can migrate the loader into another process.

T1055.001
Dynamic-link Library Injection

Lizar has used the PowerKatz plugin that can be loaded into the address space of a PowerShell process through reflective DLL loading.

T1055.002
Portable Executable Injection

Lizar can execute PE files in the address space of the specified process.

T1057
Process Discovery

Lizar has a plugin designed to obtain a list of processes.

T1059.001
PowerShell

Lizar has used PowerShell scripts.

T1059.003
Windows Command Shell

Lizar has a command to open the command-line on the infected system.

T1059.006
Python

Lizar has used Python scripts (ps2x.py script and ps2p.py) to execute files on remote hosts using the Impacket library.

T1082
System Information Discovery

Lizar can collect the computer name from the machine.

T1087.003
Email Account

Lizar can collect email accounts from Microsoft Outlook and Mozilla Thunderbird.

T1095
Non-Application Layer Protocol

Lizar has used a raw TCP connection to communicate with the C2 server.

View all 28 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. BiZone Lizar May 2021 Open source
    BI.ZONE Cyber Threats Research Team. (2021, May 13). From pentest to APT attack: cybercriminal group FIN7 disguises its malware as an ethical hacker’s toolkit. Retrieved February 2, 2022.
  2. Gemini FIN7 Oct 2021 Open source
    Gemini Advisory. (2021, October 21). FIN7 Recruits Talent For Push Into Ransomware. Retrieved February 2, 2022.
  3. Threatpost Lizar May 2021 Open source
    Seals, T. (2021, May 14). FIN7 Backdoor Masquerades as Ethical Hacking Tool. Retrieved February 2, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.