CASTLETAP

S1224

Malware.View on attack.mitre.org

About this malware

CASTLETAP is an ICMP port knocking backdoor that has been installed on compromised FortiGate firewalls by UNC3886.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1005
Data from Local System

CASTLETAP can execute a C2 command to transfer files from victim machines.

T1040
Network Sniffing

CASTLETAP has the ability to create a raw promiscuous socket to sniff network traffic.

T1059.004
Unix Shell

CASTLETAP has the ability to spawn BusyBox command shell in victim environments.

T1105
Ingress Tool Transfer

CASTLETAP can transfer files to compromised network devices.

T1140
Deobfuscate/Decode Files or Information

CASTLETAP can filter and deobfuscate an XOR encrypted activation string in the payload of an ICMP echo request.

T1205.002
Socket Filters

CASTLETAP can listen for a specialized ICMP packet for activation on compromised network devices.

T1573.001
Symmetric Cryptography

CASTLETAP can receive a 9-byte XOR encrypted activation string in the payload of an ICMP echo request packet.

T1573.002
Asymmetric Cryptography

CASTLETAP can initiate a C2 connection over an SSL socket.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Mandiant Fortinet Zero Day Open source
    Marvi, A. et al.. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved March 22, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.