OutSteel

S1017

Malware.View on attack.mitre.org

About this malware

OutSteel is a file uploader and document stealer developed with the scripting language AutoIT that has been used by Saint Bear since at least March 2021.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1005
Data from Local System

OutSteel can collect information from a compromised host.

T1020
Automated Exfiltration

OutSteel can automatically upload collected files to its C2 server.

T1036.005
Match Legitimate Resource Name or Location

OutSteel attempts to download and execute Saint Bot to a statically-defined location attempting to mimic svchost: %TEMP%\\svjhost.exe.

T1041
Exfiltration Over C2 Channel

OutSteel can upload files from a compromised host over its C2 channel.

T1057
Process Discovery

OutSteel can identify running processes on a compromised host.

T1059.003
Windows Command Shell

OutSteel has used `cmd.exe` to scan a compromised host for specific file extensions.

T1059.010
AutoHotKey & AutoIT

OutSteel was developed using the AutoIT scripting language.

T1070.004
File Deletion

OutSteel can delete itself following the successful execution of a follow-on payload.

T1071.001
Web Protocols

OutSteel has used HTTP for C2 communications.

T1083
File and Directory Discovery

OutSteel can search for specific file extensions, including zipped files.

T1105
Ingress Tool Transfer

OutSteel can download files from its C2 server.

T1119
Automated Collection

OutSteel can automatically scan for and collect files with specific extensions.

T1204.001
Malicious Link

OutSteel has relied on a user to click a malicious link within a spearphishing email.

T1204.002
Malicious File

OutSteel has relied on a user to execute a malicious attachment delivered via spearphishing.

T1566.001
Spearphishing Attachment

OutSteel has been distributed as a malicious attachment within a spearphishing email.

View all 17 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Palo Alto Unit 42 OutSteel SaintBot February 2022 Open source
    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.