Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Then, the spreader will look for any .lnk files and will replace their path with: ‘ /C start "" "<original_filename>\\" && start "" "<malicious_filename>_l.exe" ‘.
Installation of UPAS or Kronos on a computer removes, replaces, and modifies space and information on that computer thereby impairing the integrity and availability of data, a program, a system, and information on the computer.
In 32 bit systems it would create the ‘explorer.exe’ process and inject its own image into it, whereas in 64 bit systems it would do so for the 32 bit version of ‘iexplore.exe’.
Installation of UPAS or Kronos on a computer removes, replaces, and modifies space and information on that computer thereby impairing the integrity and availability of data, a program, a system, and information on the computer.
Process Injection The injection conducted by the malware depends on the system architecture... it would create the ‘explorer.exe’ process and inject its own image into it... Finally... adjust the value of EAX in the Context struct... and then resume execution by calling the NtSetContextThread function. If this fails, it will attempt to spawn the target function directly with the CreateRemoteThread function.
If this fails, it will attempt to spawn the target function (and not the call stub) directly with the CreateRemoteThread function.
Finally, in order to trigger the execution of the requested function in the remote process, the malware will set the entry point of the remote process by adjusting the value of EAX in the Context struct to that of the call stub function, and then resume execution by calling the NtSetContextThread function.
both present an attempt to elevate the malware’s process token to SeDebugPrivilege, which is not mandatory for the injection to succeed.
In 32 bit systems it would create the ‘explorer.exe’ process and inject its own image into it, whereas in 64 bit systems it would do so for the 32 bit version of ‘iexplore.exe’.
User Land Rootkit Functionality UPAS Kit uses a pretty straight forward inline hooking mechanism... The following ntdll.dll functions are hooked and are intended to hide the malware’s artifacts, thus making it covert.
UPAS Kit makes usage of multiple low-level ntdll functions and resolves their addresses during run-time... It simply takes the string field of each entry and resolves the corresponding address using the Win32 API function GetProcAddress.
First it copies itself into a new directory under %APPDATA%, named ‘Microsoft’ as well as to the %TEMP% directory.
Process Injection The injection conducted by the malware depends on the system architecture... it would create the ‘explorer.exe’ process and inject its own image into it... Finally... adjust the value of EAX in the Context struct... and then resume execution by calling the NtSetContextThread function. If this fails, it will attempt to spawn the target function directly with the CreateRemoteThread function.
If this fails, it will attempt to spawn the target function (and not the call stub) directly with the CreateRemoteThread function.
Finally, in order to trigger the execution of the requested function in the remote process, the malware will set the entry point of the remote process by adjusting the value of EAX in the Context struct to that of the call stub function, and then resume execution by calling the NtSetContextThread function.
The following ntdll.dll functions are hooked and are intended to hide the malware’s artifacts... NtQueryDirectoryFile: Hides the directory in which the malware copy resides... NtEnumerateValueKey: Hides the registry run key corresponding to the malware... NtWriteFile: Avoids the action if the target file is the malware’s binary.
both present an attempt to elevate the malware’s process token to SeDebugPrivilege, which is not mandatory for the injection to succeed.
The second technique is fairly well-known, and that is a check of VMWare’s artifact in a response from a virtual I/O port used for communication between the guest and host. | Anti-VM In order to avoid execution in analysis environments, the malware employs two techniques. The first one avoids detection by the ThreatExpert sandbox... The second technique is fairly well-known, and that is a check of VMWare’s artifact in a response from a virtual I/O port used for communication between the guest and host.
UPAS and Kronos are similar types of malware that utilize, among other things, form grabbers, key loggers, and web injects to intercept communications and collect personal information, including usernames, passwords, email addresses, and financial data, from any number of victim computers.
UPAS and Kronos are similar types of malware that utilize, among other things, form grabbers, key loggers, and web injects to intercept communications and collect personal information... The advertisement stated: "Kronos has an advanced Formigrabber that doesn't use methods publicly available. It logs ALL POST request and returns the data to the control panel."
Finally, the malware will establish the current system architecture using the function IsWow64Process, or GetNativeSystemInfo if the former is not available, and return it to the main function.
The second technique is fairly well-known, and that is a check of VMWare’s artifact in a response from a virtual I/O port used for communication between the guest and host. | Anti-VM In order to avoid execution in analysis environments, the malware employs two techniques. The first one avoids detection by the ThreatExpert sandbox... The second technique is fairly well-known, and that is a check of VMWare’s artifact in a response from a virtual I/O port used for communication between the guest and host.
UPAS and Kronos are similar types of malware that utilize, among other things, form grabbers, key loggers, and web injects to intercept communications and collect personal information, including usernames, passwords, email addresses, and financial data, from any number of victim computers.
UPAS and Kronos are similar types of malware that utilize, among other things, form grabbers, key loggers, and web injects to intercept communications and collect personal information... The advertisement stated: "Kronos has an advanced Formigrabber that doesn't use methods publicly available. It logs ALL POST request and returns the data to the control panel."
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A banking trojan that Hutchins was charged with developing, advertising, selling, and distributing.
A covert downloader malware with user-land rootkit functionality. It persists via %APPDATA% and registry run keys, injects into processes, hooks ntdll functions to hide artifacts, spreads via USB/autorun and malicious .lnk modification, and communicates with a C2 server over HTTP to receive uninstall, update, and execute commands.
Predecessor malware kit to Kronos; referenced as an earlier banking-malware codebase/toolkit used in its development lineage.
Malware similar to Kronos that uses form grabbers, key loggers, and web injects to intercept communications and collect usernames, passwords, email addresses, and financial data from victim computers. It was designed to install silently, avoid antivirus detection, target banking information, and support browsers including Internet Explorer, Firefox, and Chrome.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.