After successful exploitation and decoding of the embedded payload, a family of malware we refer to as MSIL/Crimson will be executed on the victim’s machine. The first stage in infection is a downloader whose purpose is to download the more fully featured RAT component.
Crimson
Crimson, also referred to as MSIL/Crimson, is a modular .NET remote access trojan (RAT) associated with Transparent Tribe.
Profile source: Mallory opens in a new tabCrimson
Family profile
Crimson, also referred to as MSIL/Crimson, is a modular .NET remote access trojan (RAT) associated with Transparent Tribe. Reporting tied it to Operation Transparent Tribe, which targeted Indian diplomatic and military personnel through spearphishing emails, malicious websites, and weaponized documents exploiting CVE-2012-0158; one described infection chain used an exploit document to drop a downloader that retrieved the fuller-featured RAT from 213.136.87[.]122:10001. Transparent Tribe campaigns also used malicious VBA/VBS-based lures and drive-by pages to deliver Crimson alongside other tools.
Documented Crimson capabilities are consistent with espionage use. It can exfiltrate stolen information over its command-and-control channel using a custom TCP protocol; capture screenshots; capture webcam video; perform microphone/audio surveillance; identify the current user; identify the geographical location of the victim host; discover removable/pluggable drives; collect data from removable drives; steal credentials from web browsers; query installed anti-virus software; delete files from a compromised host; and use a Registry key to track installation duration and possibly versioning. Specifically, it checks HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\last_edate to determine how long it has been installed, and reporting also states it can set a Registry key for similar install-tracking/version purposes.
Additional reporting on MSIL/Crimson states it supports file theft, Outlook email theft, microphone recording, keylogging, browser credential theft, screenshots, webcam capture, and USB file collection. Observed infrastructure and indicators in the provided content include 213.136.87[.]122:10001, 193.37.152[.]28:9990, 5.189.145[.]248:10032, and lure- or delivery-related domains such as intribune.blogspot[.]com, avadhnama[.]com, cdrfox[.]xyz, afgcloud7[.]com, bbmsync2727[.]com, and attachment[.]biz subdomains.
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to Crimson
2 CVEsMITRE ATT&CK
Crimson in ATT&CK
43 distinct techniquesTechniques
43 techniquesReporting
Research mentioning Crimson
System Location Discovery, Technique T1614 - Enterprise | MITRE ATT&CK®
Crimson can identify the geographical location of a victim host.
Updates - Updates - October 2021 | MITRE ATT&CK®
Software changes: ... Crimson
Command and Scripting Interpreter: Visual Basic, Sub-technique T1059.005 - Enterprise | MITRE ATT&CK®
Transparent Tribe used malicious VBA macros within a lure document as part of the Crimson malware installation process onto a compromised host.
Audio Capture, Technique T1123 - Enterprise | MITRE ATT&CK®
Crimson can perform audio surveillance using microphones.
Query Registry, Technique T1012 - Enterprise | MITRE ATT&CK®
Crimson can check the Registry for the presence of HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\last_edate to determine how long it has been installed on a host.
Peripheral Device Discovery, Technique T1120 - Enterprise | MITRE ATT&CK®
Crimson has the ability to discover pluggable/removable drives to extract files from.
Software Discovery: Security Software Discovery, Sub-technique T1518.001 - Enterprise | MITRE ATT&CK®
Crimson contains a command to collect information about anti-virus software on the victim.
Query Registry, Technique T1012 - Enterprise | MITRE ATT&CK®
Crimson can check the Registry for the presence of HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\last_edate to determine how long it has been installed on a host.