Emissary is a Trojan that has been used byLotus Blossom. It shares code withElise, with both Trojans being part of a malware group referred to as LStudio.[1]
| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1071 | .001 | Application Layer Protocol:Web Protocols | |
| Enterprise | T1547 | .001 | Boot or Logon Autostart Execution:Registry Run Keys / Startup Folder | Variants ofEmissary have added Run Registry keys to establish persistence.[2] |
| Enterprise | T1059 | .003 | Command and Scripting Interpreter:Windows Command Shell | Emissary has the capability to create a remote shell and execute specified commands.[1] |
| Enterprise | T1543 | .003 | Create or Modify System Process:Windows Service | |
| Enterprise | T1573 | .001 | Encrypted Channel:Symmetric Cryptography | The C2 server response to a beacon sent by a variant ofEmissary contains a 36-character GUID value that is used as an encryption key for subsequent network communications. Some variants ofEmissary use various XOR operations to encrypt C2 data.[1] |
| Enterprise | T1615 | Group Policy Discovery | ||
| Enterprise | T1105 | Ingress Tool Transfer | Emissary has the capability to download files from the C2 server.[1] | |
| Enterprise | T1027 | .001 | Obfuscated Files or Information:Binary Padding | A variant ofEmissary appends junk data to the end of its DLL file to create a large file that may exceed the maximum size that anti-virus programs can scan.[2] |
| .013 | Obfuscated Files or Information:Encrypted/Encoded File | Variants ofEmissary encrypt payloads using various XOR ciphers, as well as a custom algorithm that uses the "srand" and "rand" functions.[1][2] | ||
| Enterprise | T1069 | .001 | Permission Groups Discovery:Local Groups | Emissary has the capability to execute the command |
| Enterprise | T1055 | .001 | Process Injection:Dynamic-link Library Injection | Emissary injects its DLL file into a newly spawned Internet Explorer process.[1] |
| Enterprise | T1218 | .011 | System Binary Proxy Execution:Rundll32 | Variants ofEmissary have used rundll32.exe in Registry values added to establish persistence.[2] |
| Enterprise | T1082 | System Information Discovery | Emissary has the capability to execute ver and systeminfo commands.[2] | |
| Enterprise | T1016 | System Network Configuration Discovery | Emissary has the capability to execute the command | |
| Enterprise | T1007 | System Service Discovery | Emissary has the capability to execute the command | |
| ID | Name | References |
|---|---|---|
| G0030 | Lotus Blossom | Lotus Blossom has usedEmissary.[1][2] |