Malware.View on attack.mitre.org
IceApple is a modular Internet Information Services (IIS) post-exploitation framework, that has been used since at least 2021 against the technology, academic, and government sectors.
| Technique | Procedure example |
|---|---|
| T1003.002 Security Account Manager |
IceApple's Credential Dumper module can dump encrypted password hashes from SAM registry keys, including `HKLM\SAM\SAM\Domains\Account\F` and `HKLM\SAM\SAM\Domains\Account\Users\*\V`. |
| T1003.004 LSA Secrets |
IceApple's Credential Dumper module can dump LSA secrets from registry keys, including: `HKLM\SECURITY\Policy\PolEKList\default`, `HKLM\SECURITY\Policy\Secrets\*\CurrVal`, and `HKLM\SECURITY\Policy\Secrets\*\OldVal`. |
| T1005 Data from Local System |
IceApple can collect files, passwords, and other data from a compromised host. |
| T1016 System Network Configuration Discovery |
The IceApple ifconfig module can iterate over all network interfaces on the host and retrieve the name, description, MAC address, DNS suffix, DNS servers, gateways, IPv4 addresses, and subnet masks. |
| T1027.010 Command Obfuscation |
IceApple can use Base64 and "junk" JavaScript code to obfuscate information. |
| T1036.005 Match Legitimate Resource Name or Location |
IceApple .NET assemblies have used `App_Web_` in their file names to appear legitimate. |
| T1041 Exfiltration Over C2 Channel |
IceApple's Multi File Exfiltrator module can exfiltrate multiple files from a compromised host as an HTTP response over C2. |
| T1056.003 Web Portal Capture |
The IceApple OWA credential logger can monitor for OWA authentication requests and log the credentials. |
| T1070.004 File Deletion |
IceApple can delete files and directories from targeted systems. |
| T1071.001 Web Protocols |
IceApple can use HTTP GET to request and pull information from C2. |
| T1082 System Information Discovery |
The IceApple Server Variable Dumper module iterates over all server variables present for the current request and returns them to the adversary. |
| T1083 File and Directory Discovery |
The IceApple Directory Lister module can list information about files and directories including creation time, last write time, name, and size. |
| T1087.002 Domain Account |
The IceApple Active Directory Querier module can perform authenticated requests against an Active Directory server. |
| T1140 Deobfuscate/Decode Files or Information |
IceApple can use a Base64-encoded AES key to decrypt tasking. |
| T1505.004 IIS Components |
IceApple is an IIS post-exploitation framework, consisting of 18 modules that provide several functionalities. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.