Ninja

S1100

Malware.View on attack.mitre.org

About this malware

Ninja is a malware developed in C++ that has been used by ToddyCat to penetrate networks and control remote systems since at least 2020. Ninja is possibly part of a post exploitation toolkit exclusively used by ToddyCat and allows multiple operators to work simultaneously on the same machine. Ninja has been used against government and military entities in Europe and Asia and observed in specific infection chains being deployed by Samurai.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1001
Data Obfuscation

Ninja has the ability to modify headers and URL paths to hide malicious traffic in HTTP requests.

T1001.003
Protocol or Service Impersonation

Ninja has the ability to mimic legitimate services with customized HTTP URL paths and headers to hide malicious traffic.

T1016
System Network Configuration Discovery

Ninja can enumerate the IP address on compromised systems.

T1027.013
Encrypted/Encoded File

The Ninja payload is XOR encrypted and compressed. Ninja has also XORed its configuration data with a constant value of `0xAA`.

T1027.015
Compression

Ninja has compressed its data with the LZSS algorithm.

T1029
Scheduled Transfer

Ninja can configure its agent to work only in specific time frames.

T1036.005
Match Legitimate Resource Name or Location

Ninja has used legitimate looking filenames for its loader including update.dll and x64.dll.

T1055
Process Injection

Ninja has the ability to inject an agent module into a new process and arbitrary shellcode into running processes.

T1057
Process Discovery

Ninja can enumerate processes on a targeted host.

T1070.006
Timestomp

Ninja can change or create the last access or write times.

T1071.001
Web Protocols

Ninja can use HTTP for C2 communications.

T1082
System Information Discovery

Ninja can obtain the computer name and information on the OS from targeted hosts.

T1083
File and Directory Discovery

Ninja has the ability to enumerate directory content.

T1090.001
Internal Proxy

Ninja can proxy C2 communications including to and from internal agents without internet connectivity.

T1090.003
Multi-hop Proxy

Ninja has the ability to use a proxy chain with up to 255 hops when using TCP.

View all 28 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Kaspersky ToddyCat June 2022 Open source
    Dedola, G. (2022, June 21). APT ToddyCat. Retrieved January 3, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.