Mongall

S1026

Malware.View on attack.mitre.org

About this malware

Mongall is a backdoor that has been used since at least 2013, including by Aoqin Dragon.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

Mongall has the ability to upload files from victim's machines.

T1027.002
Software Packing

Mongall has been packed with Themida.

T1041
Exfiltration Over C2 Channel

Mongall can upload files and information from a compromised host to its C2 server.

T1055.001
Dynamic-link Library Injection

Mongall can inject a DLL into `rundll32.exe` for execution.

T1071.001
Web Protocols

Mongall can use HTTP for C2 communication.

T1082
System Information Discovery

Mongall can retrieve the hostname via `gethostbyname`.

T1105
Ingress Tool Transfer

Mongall can download files to targeted systems.

T1120
Peripheral Device Discovery

Mongall can identify removable media attached to compromised hosts.

T1132.001
Standard Encoding

Mongall can use Base64 to encode information sent to its C2.

T1140
Deobfuscate/Decode Files or Information

Mongall has the ability to decrypt its payload prior to execution.

T1204.002
Malicious File

Mongall has relied on a user opening a malicious document for execution.

T1218.011
Rundll32

Mongall can use `rundll32.exe` for execution.

T1547.001
Registry Run Keys / Startup Folder

Mongall can establish persistence with the auto start function including using the value `EverNoteTrayUService`.

T1573.001
Symmetric Cryptography

Mongall has the ability to RC4 encrypt C2 communications.

T1680
Local Storage Discovery

Mongall can identify drives on compromised hosts.

Groups that use it1

Campaigns0

None recorded.

References1

  1. SentinelOne Aoqin Dragon June 2022 Open source
    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.