Batista, J. (2024, June 17). Latrodectus, are you coming back?. Retrieved September 13, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareLatrodectus | Latrodectus can collect data from a compromised host using a stealer module. |
| T1016 System Network Configuration Discovery |
MalwareLatrodectus | Latrodectus can discover the IP and MAC address of a targeted host. |
| T1027.013 Encrypted/Encoded File |
MalwareLatrodectus | Latrodectus has used a pseudo random number generator (PRNG) algorithm and a rolling XOR key to obfuscate strings. |
| T1041 Exfiltration Over C2 Channel |
MalwareLatrodectus | Latrodectus can exfiltrate encrypted system information to the C2 server. |
| T1047 Windows Management Instrumentation |
MalwareLatrodectus | Latrodectus has used WMI in malicious email infection chains to facilitate the installation of remotely-hosted files. |
| T1053.005 Scheduled Task |
MalwareLatrodectus | Latrodectus can create scheduled tasks for persistence. |
| T1057 Process Discovery |
MalwareLatrodectus | Latrodectus can enumerate running processes including process grandchildren on targeted hosts. |
| T1059.003 Windows Command Shell |
MalwareLatrodectus | The Latrodectus command handler can use `cmdexe` to run multiple discovery commands. |
| T1059.007 JavaScript |
MalwareLatrodectus | Latrodectus has used JavaScript files as part its infection chain during malicious spam |
| T1069.002 Domain Groups |
MalwareLatrodectus | Latrodectus can identify domain groups through `cmd.exe /c net group "Domain Admins" /domain`. |
| T1070.004 File Deletion |
MalwareLatrodectus | Latrodectus has the ability to delete itself. |
| T1071.001 Web Protocols |
MalwareLatrodectus | Latrodectus can send registration information to C2 via HTTP `POST`. |
| T1082 System Information Discovery |
MalwareLatrodectus | Latrodectus can gather operating system information. |
| T1083 File and Directory Discovery |
MalwareLatrodectus | Latrodectus can collect desktop filenames. |
| T1105 Ingress Tool Transfer |
MalwareLatrodectus | Latrodectus can download and execute PEs, DLLs, and shellcode from C2. |
| T1106 Native API |
MalwareLatrodectus | Latrodectus has used multiple Windows API post exploitation including `GetAdaptersInfo`, `CreateToolhelp32Snapshot`, and `CreateProcessW`. |
| T1135 Network Share Discovery |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c net view /all` to discover network shares. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLatrodectus | Latrodectus has the ability to deobfuscate encrypted strings. |
| T1482 Domain Trust Discovery |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c nltest /domain_trusts` to discover domain trusts. |
| T1497.001 System Checks |
MalwareLatrodectus | Latrodectus can determine if it is running in a virtualized environment by checking the OS version, checking the number of running processes, ensuring a 64-bit application is running on a 64-bit host, and checking if the host has a valid MAC address. |
| T1518.001 Security Software Discovery |
MalwareLatrodectus | Latrodectus has the ability to identify installed antivirus products. |
| T1559.001 Component Object Model |
MalwareLatrodectus | Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks. |
| T1573.001 Symmetric Cryptography |
MalwareLatrodectus | Latrodectus can send RC4 encrypted data over C2 channels. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.