GReAT. (2021, June 16). Ferocious Kitten: 6 Years of Covert Surveillance in Iran. Retrieved September 22, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareMarkiRAT | MarkiRAT can upload data from the victim's machine to the C2 server. |
| T1033 System Owner/User Discovery |
MalwareMarkiRAT | MarkiRAT can retrieve the victim’s username. |
| T1036.002 Right-to-Left Override |
GroupFerocious Kitten | Ferocious Kitten has used right-to-left override to reverse executables’ names to make them appear to have different file extensions, rather than their real ones. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMarkiRAT | MarkiRAT can masquerade as |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFerocious Kitten | Ferocious Kitten has named malicious files |
| T1041 Exfiltration Over C2 Channel |
MalwareMarkiRAT | MarkiRAT can exfiltrate locally stored data via its C2. |
| T1056.001 Keylogging |
MalwareMarkiRAT | MarkiRAT can capture all keystrokes on a compromised host. |
| T1057 Process Discovery |
MalwareMarkiRAT | MarkiRAT can search for different processes on a system. |
| T1059.003 Windows Command Shell |
MalwareMarkiRAT | MarkiRAT can utilize cmd.exe to execute commands in a victim's environment. |
| T1071.001 Web Protocols |
MalwareMarkiRAT | MarkiRAT can initiate communication over HTTP/HTTPS for its C2 server. |
| T1074.001 Local Data Staging |
MalwareMarkiRAT | MarkiRAT can store collected data locally in a created .nfo file. |
| T1082 System Information Discovery |
MalwareMarkiRAT | MarkiRAT can obtain the computer name from a compromised host. |
| T1083 File and Directory Discovery |
MalwareMarkiRAT | MarkiRAT can look for files carrying specific extensions such as: .rtf, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pps, .ppsx, .txt, .gpg, .pkr, .kdbx, .key, and .jpb. |
| T1105 Ingress Tool Transfer |
MalwareMarkiRAT | MarkiRAT can download additional files and tools from its C2 server, including through the use of BITSAdmin. |
| T1106 Native API |
MalwareMarkiRAT | MarkiRAT can run the ShellExecuteW API via the Windows Command Shell. |
| T1113 Screen Capture |
MalwareMarkiRAT | MarkiRAT can capture screenshots that are initially saved as ‘scr.jpg’. |
| T1115 Clipboard Data |
MalwareMarkiRAT | MarkiRAT can capture clipboard content. |
| T1197 BITS Jobs |
MalwareMarkiRAT | MarkiRAT can use BITS Utility to connect with the C2 server. |
| T1204.002 Malicious File |
GroupFerocious Kitten | Ferocious Kitten has attempted to convince victims to enable malicious content within a spearphishing email by including an odd decoy message. |
| T1518 Software Discovery |
MalwareMarkiRAT | MarkiRAT can check for the Telegram installation directory by enumerating the files on disk. |
| T1518.001 Security Software Discovery |
MalwareMarkiRAT | MarkiRAT can check for running processes on the victim’s machine to look for Kaspersky and Bitdefender antivirus products. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMarkiRAT | MarkiRAT can drop its payload into the Startup directory to ensure it automatically runs when the compromised system is started. |
| T1547.009 Shortcut Modification |
MalwareMarkiRAT | MarkiRAT can modify the shortcut that launches Telegram by replacing its path with the malicious payload to launch with the legitimate executable. |
| T1555.005 Password Managers |
MalwareMarkiRAT | MarkiRAT can gather information from the Keepass password manager. |
| T1566.001 Spearphishing Attachment |
GroupFerocious Kitten | Ferocious Kitten has conducted spearphishing campaigns containing malicious documents to lure victims to open the attachments. |
| T1583.001 Domains |
GroupFerocious Kitten | Ferocious Kitten has acquired domains imitating legitimate sites. |
| T1588.002 Tool |
GroupFerocious Kitten | Ferocious Kitten has obtained open source tools for its operations, including JsonCPP and Psiphon. |
| T1614.001 System Language Discovery |
MalwareMarkiRAT | MarkiRAT can use the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.