DEADEYE

S1052

Malware.View on attack.mitre.org

About this malware

DEADEYE is a malware launcher that has been used by APT41 since at least May 2021. DEADEYE has variants that can either embed a payload inside a compiled binary (DEADEYE.EMBED) or append it to the end of a file (DEADEYE.APPEND).

Techniques used12

Procedure examples12

TechniqueProcedure example
T1016
System Network Configuration Discovery

DEADEYE can discover the DNS domain name of a targeted system.

T1027.009
Embedded Payloads

The DEADEYE.EMBED variant of DEADEYE has the ability to embed payloads inside of a compiled binary.

T1027.013
Encrypted/Encoded File

DEADEYE has encrypted its payload.

T1036.004
Masquerade Task or Service

DEADEYE has used `schtasks /change` to modify scheduled tasks including `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility, \Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`.

T1059.003
Windows Command Shell

DEADEYE can run `cmd /c copy /y /b C:\Users\public\syslog_6-*.dat C:\Users\public\syslog.dll` to combine separated sections of code into a single DLL prior to execution.

T1082
System Information Discovery

DEADEYE can enumerate a victim computer's volume serial number and host name.

T1106
Native API

DEADEYE can execute the `GetComputerNameA` and `GetComputerNameExA` WinAPI functions.

T1140
Deobfuscate/Decode Files or Information

DEADEYE has the ability to combine multiple sections of a binary which were broken up to evade detection into a single .dll prior to execution.

T1218.007
Msiexec

DEADEYE can use `msiexec.exe` for execution of malicious DLL.

T1218.011
Rundll32

DEADEYE can use `rundll32.exe` for execution of living off the land binaries (lolbin) such as `SHELL32.DLL`.

T1480
Execution Guardrails

DEADEYE can ensure it executes only on intended systems by identifying the victim's volume serial number, hostname, and/or DNS domain.

T1564.004
NTFS File Attributes

The DEADEYE.EMBED variant of DEADEYE can embed its payload in an alternate data stream of a local file.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Mandiant APT41 Open source
    Rufus Brown, Van Ta, Douglas Bienstock, Geoff Ackerman, John Wolfram. (2022, March 8). Does This Look Infected? A Summary of APT41 Targeting U.S. State Governments. Retrieved July 8, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.