Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupDark Caracal | Dark Caracal collected complete contents of the 'Pictures' folder from compromised Windows systems. |
| T1027.002 Software Packing |
GroupDark Caracal | Dark Caracal has used UPX to pack Bandook. |
| T1027.013 Encrypted/Encoded File |
GroupDark Caracal | Dark Caracal has obfuscated strings in Bandook by base64 encoding, and then encrypting them. |
| T1055.012 Process Hollowing |
MalwareBandook | Bandook has been launched by starting iexplore.exe and replacing it with Bandook's payload. |
| T1059.003 Windows Command Shell |
GroupDark Caracal | Dark Caracal has used macros in Word documents that would download a second stage if executed. |
| T1071.001 Web Protocols |
GroupDark Caracal | Dark Caracal's version of Bandook communicates with their server over a TCP port using HTTP payloads Base64 encoded and suffixed with the string “&&&”. |
| T1083 File and Directory Discovery |
GroupDark Caracal | Dark Caracal collected file listings of all default Windows directories. |
| T1083 File and Directory Discovery |
MalwareCrossRAT | CrossRAT can list all files on a system. |
| T1113 Screen Capture |
GroupDark Caracal | Dark Caracal took screenshots using their Windows malware. |
| T1113 Screen Capture |
MalwareBandook | Bandook is capable of taking an image of and uploading the current desktop. |
| T1113 Screen Capture |
MalwareCrossRAT | CrossRAT is capable of taking screen captures. |
| T1189 Drive-by Compromise |
GroupDark Caracal | Dark Caracal leveraged a watering hole to serve up malicious code. |
| T1204.002 Malicious File |
GroupDark Caracal | Dark Caracal makes their malware look like Flash Player, Office, or PDF documents in order to entice a user to click on it. |
| T1218.001 Compiled HTML File |
GroupDark Caracal | Dark Caracal leveraged a compiled HTML file that contained a command to download and run an executable. |
| T1543.001 Launch Agent |
MalwareCrossRAT | CrossRAT creates a Launch Agent on macOS. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupDark Caracal | Dark Caracal's version of Bandook adds a registry key to |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCrossRAT | CrossRAT uses run keys for persistence on Windows. |
| T1566.003 Spearphishing via Service |
GroupDark Caracal | Dark Caracal spearphished victims via Facebook and Whatsapp. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.