Malware.View on attack.mitre.org
TONESHELL is a custom backdoor that has been used since at least Q1 2021. TONESHELL malware has previously been leveraged by Chinese affiliated actors identified as Mustang Panda.
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
TONESHELL used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. TONESHELL variants have utilized FakeTLS headers with the bytes `0x17 0x03 0x03` to represent TLSv1.2 and `0x17 0x03 0x04` for TLSv1.3. |
| T1010 Application Window Discovery |
TONESHELL has used `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle. |
| T1027.001 Binary Padding |
TONESHELL has used randomized padding to obfuscate payloads. |
| T1027.007 Dynamic API Resolution |
TONESHELL has utilized a modified DJB2 algorithm to resolve APIs. |
| T1027.012 LNK Icon Smuggling |
TONESHELL has been initiated using LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary. |
| T1033 System Owner/User Discovery |
TONESHELL has obtained the username from an infected host. |
| T1036.004 Masquerade Task or Service |
TONESHELL has masqueraded as the legitimate Windows utility service DISMsrv (Dism Images Servicing Utility Service). |
| T1036.005 Match Legitimate Resource Name or Location |
TONESHELL has renamed malicious files to mimic legitimate file names and file extensions. TONESHELL has also masqueraded as legitimate file names to include LogMeIn.dll. |
| T1047 Windows Management Instrumentation |
TONESHELL has used WMI queries to gather information from the system. |
| T1053.005 Scheduled Task |
TONESHELL has created scheduled tasks to maintain persistence. |
| T1055.001 Dynamic-link Library Injection |
TONESHELL has used DLL injection to execute payloads received from the C2 server. |
| T1056.001 Keylogging |
TONESHELL has capabilities to conduct keylogging. |
| T1057 Process Discovery |
TONESHELL has checked the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler. TONESHELL has also searched for running antivirus processes to include ESET’s antivirus associated executables ekrn.exe and egui.exe. |
| T1059.003 Windows Command Shell |
TONESHELL has created a reverse shell using `cmd.exe`. |
| T1070.004 File Deletion |
TONESHELL has deleted payload files received from the C2 server. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.