ATT&CKSoftwareHermeticWizard

HermeticWizard

S0698

Malware.View on attack.mitre.org

About this malware

HermeticWizard is a worm that has been used to spread HermeticWiper in attacks against organizations in Ukraine since at least 2022.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1018
Remote System Discovery

HermeticWizard can find machines on the local network by gathering known local IP addresses through `DNSGetCacheDataTable`, `GetIpNetTable`,`WNetOpenEnumW(RESOURCE_GLOBALNET, RESOURCETYPE_ANY)`,`NetServerEnum`,`GetTcpTable`, and `GetAdaptersAddresses.`

T1021.002
SMB/Windows Admin Shares

HermeticWizard can use a list of hardcoded credentials to to authenticate via NTLMSSP to the SMB shares on remote systems.

T1027.013
Encrypted/Encoded File

HermeticWizard has the ability to encrypt PE files with a reverse XOR loop.

T1036.005
Match Legitimate Resource Name or Location

HermeticWizard has been named `exec_32.dll` to mimic a legitimate MS Outlook .dll.

T1046
Network Service Discovery

HermeticWizard has the ability to scan ports on a compromised network.

T1047
Windows Management Instrumentation

HermeticWizard can use WMI to create a new process on a remote machine via `C:\windows\system32\cmd.exe /c start C:\windows\system32\\regsvr32.exe /s /iC:\windows\<filename>.dll`.

T1059.003
Windows Command Shell

HermeticWizard can use `cmd.exe` for execution on compromised hosts.

T1106
Native API

HermeticWizard can connect to remote shares using `WNetAddConnection2W`.

T1110.001
Password Guessing

HermeticWizard can use a list of hardcoded credentials in attempt to authenticate to SMB shares.

T1218.010
Regsvr32

HermeticWizard has used `regsvr32.exe /s /i` to execute malicious payloads.

T1218.011
Rundll32

HermeticWizard has the ability to create a new process using `rundll32`.

T1553.002
Code Signing

HermeticWizard has been signed by valid certificates assigned to Hermetica Digital.

T1559.001
Component Object Model

HermeticWizard can execute files on remote machines using DCOM.

T1569.002
Service Execution

HermeticWizard can use `OpenRemoteServiceManager` to create a service.

T1570
Lateral Tool Transfer

HermeticWizard can copy files to other machines on a compromised network.

View all 16 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. ESET Hermetic Wizard March 2022 Open source
    ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.