Shark

S1019

Malware.View on attack.mitre.org

About this malware

Shark is a backdoor malware written in C# and .NET that is an updated version of Milan; it has been used by HEXANE since at least July 2021.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1005
Data from Local System

Shark can upload files to its C2.

T1008
Fallback Channels

Shark can update its configuration to use a different C2 server.

T1012
Query Registry

Shark can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID.

T1027.013
Encrypted/Encoded File

Shark can use encrypted and encoded files for C2 configuration.

T1029
Scheduled Transfer

Shark can pause C2 communications for a specified time.

T1036.005
Match Legitimate Resource Name or Location

Shark binaries have been named `audioddg.pdb` and `Winlangdb.pdb` in order to appear legitimate.

T1041
Exfiltration Over C2 Channel

Shark has the ability to upload files from the compromised host over a DNS or HTTP C2 channel.

T1059.003
Windows Command Shell

Shark has the ability to use `CMD` to execute commands.

T1070.004
File Deletion

Shark can delete files downloaded to the compromised host.

T1071.001
Web Protocols

Shark has the ability to use HTTP in C2 communications.

T1071.004
DNS

Shark can use DNS in C2 communications.

T1074
Data Staged

Shark has stored information in folders named `U1` and `U2` prior to exfiltration.

T1082
System Information Discovery

Shark can collect the GUID of a targeted machine.

T1105
Ingress Tool Transfer

Shark can download additional files from its C2 via HTTP or DNS.

T1140
Deobfuscate/Decode Files or Information

Shark can extract and decrypt downloaded .zip files.

View all 17 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Accenture Lyceum Targets November 2021 Open source
    Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.
  2. ClearSky Siamesekitten August 2021 Open source
    ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.