ATT&CKSoftwareRotaJakiro

RotaJakiro

S1078

Malware.View on attack.mitre.org

About this malware

RotaJakiro is a 64-bit Linux backdoor used by APT32. First seen in 2018, it uses a plugin architecture to extend capabilities. RotaJakiro can determine it's permission level and execute according to access type (`root` or `user`).

Techniques used17

Procedure examples17

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

RotaJakiro has used the filename `systemd-daemon` in an attempt to appear legitimate.

T1037
Boot or Logon Initialization Scripts

Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.conf` file in the `/etc/init/` folder.

T1041
Exfiltration Over C2 Channel

RotaJakiro sends device and other collected data back to the C2 using the established C2 channels over TCP.

T1057
Process Discovery

RotaJakiro can monitor the `/proc/[PID]` directory of known RotaJakiro processes as a part of its persistence when executing with non-root permissions. If the process is found dead, it resurrects the process. RotaJakiro processes can be matched to an associated Advisory Lock, in the `/proc/locks` folder, to ensure it doesn't spawn more than one process.

T1082
System Information Discovery

RotaJakiro executes a set of commands to collect device information, including `uname`. Another example is the `cat /etc/*release | uniq` command used to collect the current OS distribution.

T1095
Non-Application Layer Protocol

RotaJakiro uses a custom binary protocol using a type, length, value format over TCP.

T1106
Native API

When executing with non-root permissions, RotaJakiro uses the the `shmget` API to create shared memory between other known RotaJakiro processes. RotaJakiro also uses the `execvp` API to help its dead process "resurrect".

T1119
Automated Collection

Depending on the Linux distribution, RotaJakiro executes a set of commands to collect device information and sends the collected information to the C2 server.

T1129
Shared Modules

RotaJakiro uses dynamically linked shared libraries (`.so` files) to execute additional functionality using `dlopen()` and `dlsym()`.

T1132.001
Standard Encoding

RotaJakiro uses ZLIB Compression to compresses data sent to the C2 server in the `payload` section network communication packet.

T1140
Deobfuscate/Decode Files or Information

RotaJakiro uses the AES algorithm, bit shifts in a function called `rotate`, and an XOR cipher to decrypt resources required for persistence, process guarding, and file locking. It also performs this same function on encrypted stack strings and the `head` and `key` sections in the network packet structure used for C2 communications.

T1543.002
Systemd Service

Depending on the Linux distribution and when executing with root permissions, RotaJakiro may install persistence using a `.service` file under the `/lib/systemd/system/` folder.

T1546.004
Unix Shell Configuration Modification

When executing with non-root level permissions, RotaJakiro can install persistence by adding a command to the .bashrc file that executes a binary in the `${HOME}/.gvfsd/.profile/` folder.

T1547.013
XDG Autostart Entries

When executing with user-level permissions, RotaJakiro can install persistence using a .desktop file under the `$HOME/.config/autostart/` folder.

T1559
Inter-Process Communication

When executing with non-root permissions, RotaJakiro uses the the `shmget API` to create shared memory between other known RotaJakiro processes. This allows processes to communicate with each other and share their PID.

View all 17 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. RotaJakiro 2021 netlab360 analysis Open source
    Alex Turing, Hui Wang. (2021, April 28). RotaJakiro: A long live secret backdoor with 0 VT detection. Retrieved June 14, 2023.
  2. netlab360 rotajakiro vs oceanlotus Open source
    Alex Turing. (2021, May 6). RotaJakiro, the Linux version of the OceanLotus. Retrieved June 14, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.