Malware.View on attack.mitre.org
BOOKWORM is a modular trojan known to be leveraged by Mustang Panda and was first observed utilized in 2015. BOOKWORM was later updated in late 2021 and the fall of 2022 to launch shellcode represented as UUID parameters.
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
BOOKWORM has modified HTTP POST requests to resemble legitimate communications. |
| T1027 Obfuscated Files or Information |
BOOKWORM has been delivered using self-extracting RAR archives. |
| T1027.013 Encrypted/Encoded File |
BOOKWORM has utilized Base64 encoding to obfuscate its payload. |
| T1033 System Owner/User Discovery |
BOOKWORM has obtained the username from an infected host. |
| T1036.004 Masquerade Task or Service |
BOOKWORM has created services that attempt to resemble legitimate services to include a service named `Microsoft Windows DeviceSync Service`. |
| T1056.001 Keylogging |
BOOKWORM has used its KBLogger.dll module to capture keystrokes and stored them in a folder. |
| T1070.006 Timestomp |
BOOKWORM has modified file timestamps from the export address table (EAT) to make it difficult to discern when the module was created. |
| T1071.001 Web Protocols |
BOOKWORM has communicated with its C2 via HTTP POST requests. |
| T1106 Native API |
BOOKWORM has used various Windows API calls during execution and defense evasion. BOOKWORM has created a buffer on the heap using `HeapCreate` and `HeapAlloc` which allows for copying of shell code and then execution on the heap is initiated through callback function of legitimate API functions such as `EnumChildWindows` or `EnumSystemLanguageGroupsA`. |
| T1112 Modify Registry |
BOOKWORM has modified Registry key values as part of its created service `DeviceSync`. |
| T1115 Clipboard Data |
BOOKWORM has used its KBLogger.dll module to steal data saved to the clipboard. |
| T1140 Deobfuscate/Decode Files or Information |
BOOKWORM has decoded its Base64 encoded payload prior to execution. BOOKWORM has also encrypted files with RC4 and has decrypted its payload prior to execution. |
| T1543.003 Windows Service |
BOOKWORM has created a service named `Microsoft Windows DeviceSync Service` at `HKLM\SYSTEM\CurrentControlSet\Services\DeviceSync\` to trigger execution when the system starts and to maintain persistence. |
| T1553.002 Code Signing |
BOOKWORM has used valid legitimate digital signatures and certificates to evade detection. |
| T1564.003 Hidden Window |
BOOKWORM has created a hidden window when conducting key logging and clipboard theft through its KBLogger.dll module. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.