Cyber National Mission Force. (2022, January 12). Iranian intel cyber suite of malware uses open source tools. Retrieved September 30, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwarePowGoop | PowGoop can send HTTP GET requests to malicious servers. |
| T1071.004 DNS |
MalwareMori | Mori can use DNS tunneling to communicate with C2. |
| T1112 Modify Registry |
MalwareMori | Mori can write data to `HKLM\Software\NFC\IPA` and `HKLM\Software\NFC\` and delete Registry values. |
| T1132.002 Non-Standard Encoding |
MalwarePowGoop | PowGoop can use a modified Base64 encoding mechanism to send data to and from the C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePowGoop | PowGoop can decrypt PowerShell scripts for execution. |
| T1574.001 DLL |
MalwarePowGoop | PowGoop can side-load `Goopdate.dll` into `GoogleUpdate.exe`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.