Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareUPPERCUT | UPPERCUT can upload files to the C2 from infected machines. |
| T1047 Windows Management Instrumentation |
MalwareROAMINGHOUSE | ROAMINGHOUSE can use WMI to launch a legitimate executable later used to enable DLL sideloading. |
| T1059.003 Windows Command Shell |
GroupMirrorFace | MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation. |
| T1070.004 File Deletion |
GroupMirrorFace | MirrorFace has deleted directories containing malware and archives with files collected from the victim environment. |
| T1105 Ingress Tool Transfer |
MalwareUPPERCUT | UPPERCUT can download and upload files to and from the victim’s machine. |
| T1113 Screen Capture |
MalwareUPPERCUT | UPPERCUT can capture desktop screenshots in the PNG format and send them to the C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareROAMINGHOUSE | ROAMINGHOUSE can decode and drop a malicious ZIP file prior to execution. |
| T1204.001 Malicious Link |
MalwareROAMINGHOUSE | ROAMINGHOUSE has been executed through luring victims into clicking links to download malicious ZIP files. |
| T1204.002 Malicious File |
GroupMirrorFace | MirrorFace has lured victims into opening crafted Word, Excel, and SFX files for execution. |
| T1480 Execution Guardrails |
MalwareROAMINGHOUSE | ROAMINGHOUSE can change its execution method to create a batch file in the startup folder that executes a legitimate executable if a McAfee product is detected. |
| T1518.001 Security Software Discovery |
MalwareROAMINGHOUSE | ROAMINGHOUSE can identify McAfee applications on compromised hosts and change its execution method if one is detected. |
| T1548.002 Bypass User Account Control |
MalwareUPPERCUT | UPPERCUT contains functionality to bypass UAC. |
| T1566.002 Spearphishing Link |
GroupMirrorFace | MirrorFace has embedded OneDrive URLs in emails leading to malicious file installation. |
| T1566.002 Spearphishing Link |
MalwareROAMINGHOUSE | ROAMINGHOUSE has been distributed through phishing emails containing malicious OneDrive links. |
| T1568.002 Domain Generation Algorithms |
MalwareHiddenFace | HiddenFace has used dynamic domain generation algorithms in C2. |
| T1572 Protocol Tunneling |
MalwareHiddenFace | HiddenFace can hide its IP lookup by using DNS over HTTPS (DoH) for C2. |
| T1573.001 Symmetric Cryptography |
MalwareUPPERCUT | Some versions of UPPERCUT have used the hard-coded string “this is the encrypt key” for Blowfish encryption when communicating with a C2. Later versions have hard-coded keys uniquely for each C2 address. UPPERCUT has also used custom ChaCha20, XOR, and LZO algorithms for C2 communication. |
| T1574.001 DLL |
MalwareROAMINGHOUSE | ROAMINGHOUSE can use a legitimate EXE to sideload a malicious DLL named JSFC.dll. ROAMINGHOUSE has also used ScnCfg32.exe to sideload vsodscpl.dll to enable UPPERCUT execution. |
| T1678 Delay Execution |
MalwareUPPERCUT | UPPERCUT can use a sleep function to delay execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.