Malware.View on attack.mitre.org
Troll Stealer is an information stealer written in Go associated with Kimsuky operations. Troll Stealer has typically been delivered through a dropper disguised as a legitimate security program installation file. Troll Stealer features code similar to AppleSeed, also uniquely associated with Kimsuky operations.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Troll Stealer gathers information from infected systems such as SSH information from the victim's `.ssh` directory. Troll Stealer collects information from local FileZilla installations and Microsoft Sticky Note. |
| T1016 System Network Configuration Discovery |
Troll Stealer collects the MAC address of victim devices. |
| T1027.002 Software Packing |
Troll Stealer has been delivered as a VMProtect-packed binary. |
| T1036.005 Match Legitimate Resource Name or Location |
Troll Stealer is typically installed via a dropper file that masquerades as a legitimate security program installation file. |
| T1041 Exfiltration Over C2 Channel |
Troll Stealer exfiltrates collected information to its command and control infrastructure. |
| T1059.001 PowerShell |
Troll Stealer creates and executes a PowerShell script to delete itself. |
| T1059.003 Windows Command Shell |
Troll Stealer can create and execute Windows batch scripts. |
| T1070.004 File Deletion |
Troll Stealer creates and can execute a BAT script that will delete the malware. |
| T1071.001 Web Protocols |
Troll Stealer uses HTTP to communicate to command and control infrastructure. |
| T1074.001 Local Data Staging |
Troll Stealer encrypts gathered information on victim devices prior to exfiltrating it through command and control infrastructure. |
| T1082 System Information Discovery |
Troll Stealer can collect local system information. |
| T1083 File and Directory Discovery |
Troll Stealer can enumerate and collect items from local drives and folders. |
| T1113 Screen Capture |
Troll Stealer can capture screenshots from victim machines. |
| T1132.001 Standard Encoding |
Troll Stealer performs XOR encryption and Base64 encoding of data prior to sending to command and control infrastructure. |
| T1213 Data from Information Repositories |
Troll Stealer gathers information from the Government Public Key Infrastructure (GPKI) folder, associated with South Korean government public key infrastructure, on infected systems. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.