NightClub

S1090

Malware.View on attack.mitre.org

About this malware

NightClub is a modular implant written in C++ that has been used by MoustachedBouncer since at least 2014.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1005
Data from Local System

NightClub can use a file monitor to steal specific files from targeted systems.

T1010
Application Window Discovery

NightClub can use `GetForegroundWindow` to enumerate the active window.

T1027
Obfuscated Files or Information

NightClub can obfuscate strings using the congruential generator `(LCG): staten+1 = (690069 × staten + 1) mod 232`.

T1036.004
Masquerade Task or Service

NightClub has created a service named `WmdmPmSp` to spoof a Windows Media service.

T1036.005
Match Legitimate Resource Name or Location

NightClub has chosen file names to appear legitimate including EsetUpdate-0117583943.exe for its dropper.

T1041
Exfiltration Over C2 Channel

NightClub can use SMTP and DNS for file exfiltration and C2.

T1056.001
Keylogging

NightClub can use a plugin for keylogging.

T1057
Process Discovery

NightClub has the ability to use `GetWindowThreadProcessId` to identify the process behind a specified window.

T1070.006
Timestomp

NightClub can modify the Creation, Access, and Write timestamps for malicious DLLs to match those of the genuine Windows DLL user32.dll.

T1071.003
Mail Protocols

NightClub can use emails for C2 communications.

T1071.004
DNS

NightClub can use a DNS tunneling plugin to exfiltrate data by adding it to the subdomain portion of a DNS request.

T1074.001
Local Data Staging

NightClub has copied captured files and keystrokes to the `%TEMP%` directory of compromised hosts.

T1083
File and Directory Discovery

NightClub can use a file monitor to identify .lnk, .doc, .docx, .xls, .xslx, and .pdf files.

T1105
Ingress Tool Transfer

NightClub can load multiple additional plugins on an infected host.

T1106
Native API

NightClub can use multiple native APIs including `GetKeyState`, `GetForegroundWindow`, `GetWindowThreadProcessId`, and `GetKeyboardLayout`.

View all 21 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. MoustachedBouncer ESET August 2023 Open source
    Faou, M. (2023, August 10). MoustachedBouncer: Espionage against foreign diplomats in Belarus. Retrieved September 25, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.