NICECURL

S1192

Malware.View on attack.mitre.org

About this malware

NICECURL is a VBScript-based backdoor used by APT42 to download additional modules.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1059
Command and Scripting Interpreter

NICECURL has provided an arbitrary command execution interface.

T1070.004
File Deletion

NICECURL has a function to remove artifacts.

T1071.001
Web Protocols

NICECURL has used HTTPS for C2 communications.

T1105
Ingress Tool Transfer

NICECURL has the ability to download additional content onto an infected machine, e.g. by using `curl`.

T1573.002
Asymmetric Cryptography

NICECURL has used HTTPS for C2 communications.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Mandiant APT42-untangling Open source
    Rozmann, O., et al. (2024, May 1). Uncharmed: Untangling Iran's APT42 Operations. Retrieved October 9, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.