NOKKI
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols |
NOKKI has used HTTP for C2 communications.(Citation: Unit 42 NOKKI Sept 2018) |
.002 | Application Layer Protocol: File Transfer Protocols |
NOKKI has used FTP for C2 communications.(Citation: Unit 42 NOKKI Sept 2018) |
||
Enterprise | T1547 | .001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
NOKKI has established persistence by writing the payload to the Registry key |
Enterprise | T1074 | .001 | Data Staged: Local Data Staging |
NOKKI can collect data from the victim and stage it in |
Enterprise | T1070 | .004 | Indicator Removal: File Deletion |
NOKKI can delete files to cover tracks.(Citation: Unit 42 NOKKI Sept 2018) |
Enterprise | T1056 | .004 | Input Capture: Credential API Hooking |
NOKKI uses the Windows call SetWindowsHookEx and begins injecting it into every GUI process running on the victim's machine.(Citation: Unit 42 NOKKI Sept 2018) |
Enterprise | T1036 | .005 | Masquerading: Match Legitimate Name or Location |
NOKKI is written to %LOCALAPPDATA%\MicroSoft Updatea\svServiceUpdate.exe prior being executed in a new process in an apparent attempt to masquerade as a legitimate folder and file.(Citation: Unit 42 NOKKI Sept 2018) |
Enterprise | T1218 | .011 | System Binary Proxy Execution: Rundll32 |
NOKKI has used rundll32 for execution.(Citation: Unit 42 NOKKI Sept 2018) |
Groups That Use This Software |
||
ID | Name | References |
---|---|---|
G0094 | Kimsuky |
(Citation: Crowdstrike GTR2020 Mar 2020) |
References
- Grunzweig, J., Lee, B. (2018, September 27). New KONNI Malware attacking Eurasia and Southeast Asia. Retrieved November 5, 2018.
- Grunzweig, J. (2018, October 01). NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT. Retrieved November 5, 2018.
- Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.