Unit 42. (2022, June 13). GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool. Retrieved August 7, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwarePingPull | PingPull can collect data from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwarePingPull | PingPull can retrieve the IP address of a compromised host. |
| T1036.004 Masquerade Task or Service |
MalwarePingPull | PingPull can mimic the names and descriptions of legitimate services such as `iphlpsvc`, `IP Helper`, and `Onedrive` to evade detection. |
| T1041 Exfiltration Over C2 Channel |
MalwarePingPull | PingPull has the ability to exfiltrate stolen victim data through its C2 channel. |
| T1059.003 Windows Command Shell |
MalwarePingPull | PingPull can use `cmd.exe` to run various commands as a reverse shell. |
| T1070.006 Timestomp |
MalwarePingPull | PingPull has the ability to timestomp a file. |
| T1071.001 Web Protocols |
MalwarePingPull | A PingPull variant can communicate with its C2 servers by using HTTPS. |
| T1082 System Information Discovery |
MalwarePingPull | PingPull can retrieve the hostname of a compromised host. |
| T1083 File and Directory Discovery |
MalwarePingPull | PingPull can enumerate storage volumes and folder contents of a compromised host. |
| T1095 Non-Application Layer Protocol |
MalwarePingPull | PingPull variants have the ability to communicate with C2 servers using ICMP or TCP. |
| T1132.001 Standard Encoding |
MalwarePingPull | PingPull can encode C2 traffic with Base64. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePingPull | PingPull can decrypt received data from its C2 server by using AES. |
| T1543.003 Windows Service |
MalwarePingPull | PingPull has the ability to install itself as a service. |
| T1571 Non-Standard Port |
MalwarePingPull | PingPull can use HTTPS over port 8080 for C2. |
| T1573.001 Symmetric Cryptography |
MalwarePingPull | PingPull can use AES, in cipher block chaining (CBC) mode padded with PKCS5, to encrypt C2 server communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.