Malware.View on attack.mitre.org
STARWHALE is Windows Script File (WSF) backdoor that has been used by MuddyWater, possibly since at least November 2021; there is also a STARWHALE variant written in Golang with similar capabilities. Security researchers have also noted the use of STARWHALE by UNC3313, which may be associated with MuddyWater.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
STARWHALE can collect data from an infected local host. |
| T1016 System Network Configuration Discovery |
STARWHALE has the ability to collect the IP address of an infected host. |
| T1027.013 Encrypted/Encoded File |
STARWHALE has been obfuscated with hex-encoded strings. |
| T1033 System Owner/User Discovery |
STARWHALE can gather the username from an infected host. |
| T1041 Exfiltration Over C2 Channel |
STARWHALE can exfiltrate collected data to its C2 servers. |
| T1059.003 Windows Command Shell |
STARWHALE has the ability to execute commands via `cmd.exe`. |
| T1059.005 Visual Basic |
STARWHALE can use the VBScript function `GetRef` as part of its persistence mechanism. |
| T1071.001 Web Protocols |
STARWHALE has the ability to contact actor-controlled C2 servers via HTTP. |
| T1074.001 Local Data Staging |
STARWHALE has stored collected data in a file called `stari.txt`. |
| T1082 System Information Discovery |
STARWHALE can gather the computer name of an infected host. |
| T1132.001 Standard Encoding |
STARWHALE has the ability to hex-encode collected data from an infected host. |
| T1204.002 Malicious File |
STARWHALE has relied on victims opening a malicious Excel file for execution. |
| T1543.003 Windows Service |
STARWHALE has the ability to create the following Windows service to establish persistence on an infected host: `sc create Windowscarpstss binpath= "cmd.exe /c cscript.exe c:\\windows\\system32\\w7_1.wsf humpback_whale" start= "auto" obj= "LocalSystem"`. |
| T1547.001 Registry Run Keys / Startup Folder |
STARWHALE can establish persistence by installing itself in the startup folder, whereas the GO variant has created a `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OutlookM` registry key. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.