Trustwave SpiderLabs. (2020, June 22). Pillowmint: FIN7’s Monkey Thief . Retrieved July 27, 2020.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwarePillowmint | Pillowmint has collected credit card data using native API functions. |
| T1012 Query Registry |
MalwarePillowmint | Pillowmint has used shellcode which reads code stored in the registry keys |
| T1027 Obfuscated Files or Information |
MalwarePillowmint | Pillowmint has obfuscated the AES key used for encryption. |
| T1027.011 Fileless Storage |
MalwarePillowmint | Pillowmint has stored a compressed payload in the Registry key |
| T1027.015 Compression |
MalwarePillowmint | Pillowmint has been compressed and stored within a registry key. |
| T1055.004 Asynchronous Procedure Call |
MalwarePillowmint | Pillowmint has used the NtQueueApcThread syscall to inject code into svchost.exe. |
| T1057 Process Discovery |
MalwarePillowmint | Pillowmint can iterate through running processes every six seconds collecting a list of processes to capture from later. |
| T1059.001 PowerShell |
MalwarePillowmint | Pillowmint has used a PowerShell script to install a shim database. |
| T1070.004 File Deletion |
MalwarePillowmint | Pillowmint has deleted the filepath |
| T1070.009 Clear Persistence |
MalwarePillowmint | Pillowmint can uninstall the malicious service from an infected machine. |
| T1106 Native API |
MalwarePillowmint | Pillowmint has used multiple native Windows APIs to execute and conduct process injections. |
| T1112 Modify Registry |
MalwarePillowmint | Pillowmint has modified the Registry key |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePillowmint | Pillowmint has been decompressed by included shellcode prior to being launched. |
| T1546.011 Application Shimming |
MalwarePillowmint | Pillowmint has used a malicious shim database to maintain persistence. |
| T1560 Archive Collected Data |
MalwarePillowmint | Pillowmint has encrypted stolen credit card information with AES and further encoded it with Base64. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.