Spica

S1140

Malware.View on attack.mitre.org

About this malware

Spica is a custom backdoor written in Rust that has been used by Star Blizzard since at least 2023.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1036.004
Masquerade Task or Service

Spica has created a scheduled task named `CalendarChecker` for persistence on compromised hosts.

T1053.005
Scheduled Task

Spica has created a scheduled task named `CalendarChecker` to establish persistence.

T1059.001
PowerShell

Spica can use an obfuscated PowerShell command to create a scheduled task for persistence.

T1083
File and Directory Discovery

Spica can list filesystem contents on targeted systems.

T1095
Non-Application Layer Protocol

Spica can use JSON over WebSockets for C2 communications.

T1105
Ingress Tool Transfer

Spica can upload and download files to and from compromised hosts.

T1140
Deobfuscate/Decode Files or Information

Upon execution Spica can decode an embedded .pdf and write it to the desktop as a decoy document.

T1539
Steal Web Session Cookie

Spica has the ability to steal cookies from Chrome, Firefox, Opera, and Edge browsers.

T1560
Archive Collected Data

Spica can archive collected documents for exfiltration.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Google TAG COLDRIVER January 2024 Open source
    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.