FireEye. (2014). POISON IVY: Assessing Damage and Extracting Intelligence. Retrieved September 19, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.001 Dynamic-link Library Injection |
MalwarePoisonIvy | PoisonIvy can inject a malicious DLL into a process. |
| T1056.001 Keylogging |
MalwarePoisonIvy | PoisonIvy contains a keylogger. |
| T1480.002 Mutual Exclusion |
MalwarePoisonIvy | PoisonIvy creates a mutex using either a custom or default value. |
| T1573.001 Symmetric Cryptography |
MalwarePoisonIvy | PoisonIvy uses the Camellia cipher to encrypt communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.