ObliqueRAT
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1547 | .001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
ObliqueRAT can gain persistence by a creating a shortcut in the infected user's Startup directory.(Citation: Talos Oblique RAT March 2021) |
Enterprise | T1074 | .001 | Data Staged: Local Data Staging |
ObliqueRAT can copy specific files, webcam captures, and screenshots to local directories.(Citation: Talos Oblique RAT March 2021) |
Enterprise | T1027 | .003 | Obfuscated Files or Information: Steganography |
ObliqueRAT can hide its payload in BMP images hosted on compromised websites.(Citation: Talos Oblique RAT March 2021) |
Enterprise | T1204 | .001 | User Execution: Malicious Link |
ObliqueRAT has gained execution on targeted systems through luring users to click on links to malicious URLs.(Citation: Talos Oblique RAT March 2021)(Citation: Talos Transparent Tribe May 2021) |
Enterprise | T1497 | .001 | Virtualization/Sandbox Evasion: System Checks |
ObliqueRAT can halt execution if it identifies processes belonging to virtual machine software or analysis tools.(Citation: Talos Oblique RAT March 2021) |
Groups That Use This Software |
||
ID | Name | References |
---|---|---|
G0134 | Transparent Tribe |
(Citation: Talos Oblique RAT March 2021) (Citation: Cisco Talos Transparent Tribe Education Campaign July 2022) |
References
- Malhotra, A. (2021, March 2). ObliqueRAT returns with new campaign using hijacked websites. Retrieved September 2, 2021.
- Malhotra, A. et al. (2021, May 13). Transparent Tribe APT expands its Windows malware arsenal. Retrieved September 2, 2021.
- N. Baisini. (2022, July 13). Transparent Tribe begins targeting education sector in latest campaign. Retrieved September 22, 2022.
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.