ATT&CKReferencesCyberBit Early Bird Apr 2018

CyberBit Early Bird Apr 2018

Gavriel, H. & Erbesfeld, B. (2018, April 11). New ‘Early Bird’ Code Injection Technique Discovered. Retrieved May 24, 2018.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1055.004
Asynchronous Procedure Call
MalwareTURNEDUP

TURNEDUP is capable of injecting code into the APC queue of a created Rundll32 process as part of an "Early Bird injection."

T1547.001
Registry Run Keys / Startup Folder
MalwareTURNEDUP

TURNEDUP is capable of writing to a Registry Run key to establish.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.