ATT&CKSoftwareHeyoka Backdoor

Heyoka Backdoor

S1027

Malware.View on attack.mitre.org

About this malware

Heyoka Backdoor is a custom backdoor--based on the Heyoka open source exfiltration tool--that has been used by Aoqin Dragon since at least 2013.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1007
System Service Discovery

Heyoka Backdoor can check if it is running as a service on a compromised host.

T1027.013
Encrypted/Encoded File

Heyoka Backdoor can encrypt its payload.

T1036.004
Masquerade Task or Service

Heyoka Backdoor has been named `srvdll.dll` to appear as a legitimate service.

T1055.001
Dynamic-link Library Injection

Heyoka Backdoor can inject a DLL into rundll32.exe for execution.

T1057
Process Discovery

Heyoka Backdoor can gather process information.

T1070.004
File Deletion

Heyoka Backdoor has the ability to delete folders and files from a targeted system.

T1071.004
DNS

Heyoka Backdoor can use DNS tunneling for C2 communications.

T1083
File and Directory Discovery

Heyoka Backdoor has the ability to search the compromised host for files.

T1120
Peripheral Device Discovery

Heyoka Backdoor can identify removable media attached to victim's machines.

T1140
Deobfuscate/Decode Files or Information

Heyoka Backdoor can decrypt its payload prior to execution.

T1204.002
Malicious File

Heyoka Backdoor has been spread through malicious document lures.

T1218.011
Rundll32

Heyoka Backdoor can use rundll32.exe to gain execution.

T1547.001
Registry Run Keys / Startup Folder

Heyoka Backdoor can establish persistence with the auto start function including using the value `EverNoteTrayUService`.

T1572
Protocol Tunneling

Heyoka Backdoor can use spoofed DNS requests to create a bidirectional tunnel between a compromised host and its C2 servers.

T1680
Local Storage Discovery

Heyoka Backdoor can enumerate drives on a compromised host.

Groups that use it1

Campaigns0

None recorded.

References2

  1. SentinelOne Aoqin Dragon June 2022 Open source
    Chen, Joey. (2022, June 9). Aoqin Dragon | Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For 10 Years. Retrieved July 14, 2022.
  2. Sourceforge Heyoka 2022 Open source
    Sourceforge. (n.d.). Heyoka POC Exfiltration Tool. Retrieved October 11, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.