ATT&CKReferencesCYBERCOM Iranian Intel Cyber January 2022

CYBERCOM Iranian Intel Cyber January 2022

Cyber National Mission Force. (2022, January 12). Iranian intel cyber suite of malware uses open source tools. Retrieved September 30, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwarePowGoop

PowGoop can send HTTP GET requests to malicious servers.

T1071.004
DNS
MalwareMori

Mori can use DNS tunneling to communicate with C2.

T1112
Modify Registry
MalwareMori

Mori can write data to `HKLM\Software\NFC\IPA` and `HKLM\Software\NFC\` and delete Registry values.

T1132.002
Non-Standard Encoding
MalwarePowGoop

PowGoop can use a modified Base64 encoding mechanism to send data to and from the C2 server.

T1140
Deobfuscate/Decode Files or Information
MalwarePowGoop

PowGoop can decrypt PowerShell scripts for execution.

T1574.001
DLL
MalwarePowGoop

PowGoop can side-load `Goopdate.dll` into `GoogleUpdate.exe`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.