Malware.View on attack.mitre.org
Action RAT is a remote access tool written in Delphi that has been used by SideCopy since at least December 2021 against Indian and Afghani government personnel.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Action RAT can collect local data from an infected machine. |
| T1016 System Network Configuration Discovery |
Action RAT has the ability to collect the MAC address of an infected host. |
| T1027 Obfuscated Files or Information |
Action RAT's commands, strings, and domains can be Base64 encoded within the payload. |
| T1033 System Owner/User Discovery |
Action RAT has the ability to collect the username from an infected host. |
| T1047 Windows Management Instrumentation |
Action RAT can use WMI to gather AV products installed on an infected host. |
| T1059.003 Windows Command Shell |
Action RAT can use `cmd.exe` to execute commands on an infected host. |
| T1071.001 Web Protocols |
Action RAT can use HTTP to communicate with C2 servers. |
| T1082 System Information Discovery |
Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host. |
| T1083 File and Directory Discovery |
Action RAT has the ability to collect drive and file information on an infected machine. |
| T1105 Ingress Tool Transfer |
Action RAT has the ability to download additional payloads onto an infected machine. |
| T1140 Deobfuscate/Decode Files or Information |
Action RAT can use Base64 to decode actor-controlled C2 server communications. |
| T1518.001 Security Software Discovery |
Action RAT can identify AV products on an infected host using the following command: `cmd.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.