GReAT. (2019, April 10). Project TajMahal – a sophisticated new APT framework. Retrieved October 14, 2019.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareTajMahal | TajMahal has the ability to steal documents from the local system including the print spooler queue. |
| T1016 System Network Configuration Discovery |
MalwareTajMahal | TajMahal has the ability to identify the MAC address on an infected host. |
| T1020 Automated Exfiltration |
MalwareTajMahal | TajMahal has the ability to manage an automated queue of egress files and commands sent to its C2. |
| T1025 Data from Removable Media |
MalwareTajMahal | TajMahal has the ability to steal written CD images and files of interest from previously connected removable drives when they become available again. |
| T1027 Obfuscated Files or Information |
MalwareTajMahal | TajMahal has used an encrypted Virtual File System to store plugins. |
| T1041 Exfiltration Over C2 Channel |
MalwareTajMahal | TajMahal has the ability to send collected files over its C2. |
| T1055.001 Dynamic-link Library Injection |
MalwareTajMahal | TajMahal has the ability to inject DLLs for malicious plugins into running processes. |
| T1056.001 Keylogging |
MalwareTajMahal | TajMahal has the ability to capture keystrokes on an infected host. |
| T1057 Process Discovery |
MalwareTajMahal | TajMahal has the ability to identify running processes and associated plugins on an infected host. |
| T1082 System Information Discovery |
MalwareTajMahal | TajMahal has the ability to identify hardware information, the computer name, and OS information on an infected host. |
| T1083 File and Directory Discovery |
MalwareTajMahal | TajMahal has the ability to index files from drives, user profiles, and removable drives. |
| T1112 Modify Registry |
MalwareTajMahal | TajMahal can set the |
| T1113 Screen Capture |
MalwareTajMahal | TajMahal has the ability to take screenshots on an infected host including capturing content from windows of instant messaging applications. |
| T1115 Clipboard Data |
MalwareTajMahal | TajMahal has the ability to steal data from the clipboard of an infected host. |
| T1119 Automated Collection |
MalwareTajMahal | TajMahal has the ability to index and compress files into a send queue for exfiltration. |
| T1120 Peripheral Device Discovery |
MalwareTajMahal | TajMahal has the ability to identify connected Apple devices. |
| T1123 Audio Capture |
MalwareTajMahal | TajMahal has the ability to capture VoiceIP application audio on an infected host. |
| T1124 System Time Discovery |
MalwareTajMahal | TajMahal has the ability to determine local time on a compromised host. |
| T1125 Video Capture |
MalwareTajMahal | TajMahal has the ability to capture webcam video. |
| T1129 Shared Modules |
MalwareTajMahal | TajMahal has the ability to inject the |
| T1518 Software Discovery |
MalwareTajMahal | TajMahal has the ability to identify the Internet Explorer (IE) version on an infected host. |
| T1518.001 Security Software Discovery |
MalwareTajMahal | TajMahal has the ability to identify which anti-virus products, firewalls, and anti-spyware products are in use. |
| T1539 Steal Web Session Cookie |
MalwareTajMahal | TajMahal has the ability to steal web session cookies from Internet Explorer, Netscape Navigator, FireFox and RealNetworks applications. |
| T1560.002 Archive via Library |
MalwareTajMahal | TajMahal has the ability to use the open source libraries XZip/Xunzip and zlib to compress files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.