Audio Capture

An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listening into sensitive conversations to gather information.

Malware or scripts may be used to interact with the devices through an available API provided by the operating system or an application to capture audio. Audio files may be written to disk and exfiltrated later.

ID: T1123

Tactic: Collection

Platform:  Linux, macOS, Windows

Permissions Required:  User

Data Sources:  API monitoring, Process monitoring, File monitoring

Version: 1.0

Examples

NameDescription
APT37

APT37 has used an audio capturing utility known as SOUNDWAVE that captures microphone input.[1]

Bandook

Bandook has modules that are capable of capturing audio.[2]

Cobian RAT

Cobian RAT has a feature to perform voice recording on the victim’s machine.[3]

DarkComet

DarkComet can listen in to victims' conversations through the system’s microphone.[4][5]

Derusbi

Derusbi is capable of performing audio captures.[6]

DOGCALL

DOGCALL can capture microphone data from the victim's machine.[7]

EvilGrab

EvilGrab has the capability to capture audio from a victim machine.[8]

Flame

Flame can record audio using any existing hardware recording devices.[9][10]

InvisiMole

InvisiMole can record sound using input audio devices.[11]

Janicab

Janicab captured audio and sent it out to a C2 server.[12][13]

jRAT

jRAT can capture microphone recordings.[14]

MacSpy

MacSpy can record the sounds from microphones on a computer.[15]

Micropsia

Micropsia can perform microphone recording.[16]

NanoCore

NanoCore can capture audio feeds from the system.[17][18]

PowerSploit

PowerSploit's Get-MicrophoneAudio Exfiltration module can record system microphone audio.[19][20]

Pupy

Pupy can record sound with the microphone.[21]

Remcos

Remcos can capture data from the system’s microphone.[22]

T9000

T9000 uses the Skype API to record audio and video calls. It writes encrypted data to %APPDATA%\Intel\Skype.[23]

VERMIN

VERMIN can perform audio capture.[24]

Mitigation

Mitigating this technique specifically may be difficult as it requires fine-grained API control. Efforts should be focused on preventing unwanted or unknown code from executing on a system.

Identify and block potentially malicious software that may be used to record audio by using whitelisting [25] tools, like AppLocker, [26] [27] or Software Restriction Policies [28] where appropriate. [29]

Detection

Detection of this technique may be difficult due to the various APIs that may be used. Telemetry data regarding API use may not be useful depending on how a system is normally used, but may provide context to other potentially malicious activity occurring on a system.

Behavior that could indicate technique use include an unknown or unusual process accessing APIs associated with devices or software that interact with the microphone, recording devices, or recording software, and a process periodically writing files to disk that contain audio data.

References

  1. FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved March 1, 2018.
  2. Galperin, E., Et al.. (2016, August). I Got a Letter From the Government the Other Day.... Retrieved April 25, 2018.
  3. Yadav, A., et al. (2017, August 31). Cobian RAT – A backdoored RAT. Retrieved November 13, 2018.
  4. TrendMicro. (2014, September 03). DARKCOMET. Retrieved November 6, 2018.
  5. Kujawa, A. (2018, March 27). You dirty RAT! Part 1: DarkComet. Retrieved November 6, 2018.
  6. FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.
  7. Grunzweig, J. (2018, October 01). NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT. Retrieved November 5, 2018.
  8. PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.
  9. Gostev, A. (2012, May 28). The Flame: Questions and Answers. Retrieved March 1, 2017.
  10. Gostev, A. (2012, May 30). Flame: Bunny, Frog, Munch and BeetleJuice…. Retrieved March 1, 2017.
  11. Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.
  12. Brod. (2013, July 15). Signed Mac Malware Using Right-to-Left Override Trick. Retrieved July 17, 2017.
  13. Thomas. (2013, July 15). New signed malware called Janicab. Retrieved July 17, 2017.
  14. Kamluk, V. & Gostev, A. (2016, February). Adwind - A Cross-Platform RAT. Retrieved April 23, 2019.
  15. Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018.