ATT&CKReferencesTrustwave Pillowmint June 2020

Trustwave Pillowmint June 2020

Trustwave SpiderLabs. (2020, June 22). Pillowmint: FIN7’s Monkey Thief . Retrieved July 27, 2020.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwarePillowmint

Pillowmint has collected credit card data using native API functions.

T1012
Query Registry
MalwarePillowmint

Pillowmint has used shellcode which reads code stored in the registry keys \REGISTRY\SOFTWARE\Microsoft\DRM using the native Windows API as well as read HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces as part of its C2.

T1027
Obfuscated Files or Information
MalwarePillowmint

Pillowmint has obfuscated the AES key used for encryption.

T1027.011
Fileless Storage
MalwarePillowmint

Pillowmint has stored a compressed payload in the Registry key HKLM\SOFTWARE\Microsoft\DRM.

T1027.015
Compression
MalwarePillowmint

Pillowmint has been compressed and stored within a registry key.

T1055.004
Asynchronous Procedure Call
MalwarePillowmint

Pillowmint has used the NtQueueApcThread syscall to inject code into svchost.exe.

T1057
Process Discovery
MalwarePillowmint

Pillowmint can iterate through running processes every six seconds collecting a list of processes to capture from later.

T1059.001
PowerShell
MalwarePillowmint

Pillowmint has used a PowerShell script to install a shim database.

T1070.004
File Deletion
MalwarePillowmint

Pillowmint has deleted the filepath %APPDATA%\Intel\devmonsrv.exe.

T1070.009
Clear Persistence
MalwarePillowmint

Pillowmint can uninstall the malicious service from an infected machine.

T1106
Native API
MalwarePillowmint

Pillowmint has used multiple native Windows APIs to execute and conduct process injections.

T1112
Modify Registry
MalwarePillowmint

Pillowmint has modified the Registry key HKLM\SOFTWARE\Microsoft\DRM to store a malicious payload.

T1140
Deobfuscate/Decode Files or Information
MalwarePillowmint

Pillowmint has been decompressed by included shellcode prior to being launched.

T1546.011
Application Shimming
MalwarePillowmint

Pillowmint has used a malicious shim database to maintain persistence.

T1560
Archive Collected Data
MalwarePillowmint

Pillowmint has encrypted stolen credit card information with AES and further encoded it with Base64.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.