CORESHELL — Malware Profile
CORESHELL is a downloader used by APT28. The older versions of this malware are known as SOURFACE and newer versions as CORESHELL.
MITRE ATT&CK techniques (11)
- T1027 Obfuscated Files or Information
- T1027.016 Junk Code Insertion
- T1071.001 Web Protocols
- T1071.003 Mail Protocols
- T1082 System Information Discovery
- T1105 Ingress Tool Transfer
- T1132.001 Standard Encoding
- T1218.011 Rundll32
- T1547.001 Registry Run Keys / Startup Folder
- T1573.001 Symmetric Cryptography
- T1680 Local Storage Discovery