Malware.View on attack.mitre.org
KOPILUWAK is a JavaScript-based reconnaissance tool that has been used for victim profiling and C2 since at least 2017.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
KOPILUWAK can gather information from compromised hosts. |
| T1016 System Network Configuration Discovery |
KOPILUWAK can use Arp to discover a target's network configuration setttings. |
| T1033 System Owner/User Discovery |
KOPILUWAK can conduct basic network reconnaissance on the victim machine with `whoami`, to get user details. |
| T1041 Exfiltration Over C2 Channel |
KOPILUWAK has exfiltrated collected data to its C2 via POST requests. |
| T1049 System Network Connections Discovery |
KOPILUWAK can use netstat, Arp, and Net to discover current TCP connections. |
| T1057 Process Discovery |
KOPILUWAK can enumerate current running processes on the targeted machine. |
| T1059.007 JavaScript |
KOPILUWAK had used Javascript to perform its core functions. |
| T1071.001 Web Protocols |
KOPILUWAK has used HTTP POST requests to send data to C2. |
| T1074.001 Local Data Staging |
KOPILUWAK has piped the results from executed C2 commands to `%TEMP%\result2.dat` on the local machine. |
| T1135 Network Share Discovery |
KOPILUWAK can use netstat and Net to discover network shares. |
| T1204.002 Malicious File |
KOPILUWAK has gained execution through malicious attachments. |
| T1566.001 Spearphishing Attachment |
KOPILUWAK has been delivered to victims as a malicious email attachment. |
| T1680 Local Storage Discovery |
KOPILUWAK can discover logical drive information on compromised hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.