Waterbear — Malware Profile
Waterbear is modular malware attributed to BlackTech that has been used primarily for lateral movement, decrypting, and triggering payloads and is capable of hiding network behaviors.
MITRE ATT&CK techniques (14)
- T1012 Query Registry
- T1027.005 Indicator Removal from Tools
- T1027.013 Encrypted/Encoded File
- T1049 System Network Connections Discovery
- T1055 Process Injection
- T1055.003 Thread Execution Hijacking
- T1057 Process Discovery
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1112 Modify Registry
- T1140 Deobfuscate/Decode Files or Information
- T1518.001 Security Software Discovery
- T1574.001 DLL
- T1685 Disable or Modify Tools