ATT&CKReferencesKaspersky Winnti April 2013

Kaspersky Winnti April 2013

Kaspersky Lab's Global Research and Analysis Team. (2013, April 11). Winnti. More than just a game. Retrieved February 8, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups2

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1014
Rootkit
GroupWinnti Group

Winnti Group used a rootkit to modify typical server functionality.

T1057
Process Discovery
GroupWinnti Group

Winnti Group looked for a specific process running on infected servers.

T1083
File and Directory Discovery
GroupWinnti Group

Winnti Group has used a program named ff.exe to search for specific documents on compromised hosts.

T1105
Ingress Tool Transfer
GroupWinnti Group

Winnti Group has downloaded an auxiliary program named ff.exe to infected machines.

T1553.002
Code Signing
GroupWinnti Group

Winnti Group used stolen certificates to sign its malware.

T1583.001
Domains
GroupWinnti Group

Winnti Group has registered domains for C2 that mimicked sites of their intended targets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.