ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareZebrocy | Zebrocy executes the |
| T1016 System Network Configuration Discovery |
MalwareZebrocy | Zebrocy runs the |
| T1049 System Network Connections Discovery |
MalwareZebrocy | Zebrocy uses |
| T1057 Process Discovery |
MalwareZebrocy | Zebrocy uses the |
| T1059.003 Windows Command Shell |
MalwareZebrocy | Zebrocy uses cmd.exe to execute commands on the system. |
| T1070.004 File Deletion |
MalwareZebrocy | Zebrocy has a command to delete files and directories. |
| T1071.001 Web Protocols |
MalwareZebrocy | Zebrocy uses HTTP for C2. |
| T1071.003 Mail Protocols |
MalwareZebrocy | Zebrocy uses SMTP and POP3 for C2. |
| T1082 System Information Discovery |
MalwareZebrocy | Zebrocy collects the OS version and computer name. Zebrocy also runs the |
| T1083 File and Directory Discovery |
MalwareZebrocy | Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the |
| T1105 Ingress Tool Transfer |
MalwareZebrocy | Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload. |
| T1113 Screen Capture |
MalwareZebrocy | A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format. |
| T1119 Automated Collection |
MalwareZebrocy | Zebrocy scans the system and automatically collects files with the following extensions: .doc, .docx, ,.xls, .xlsx, .pdf, .pptx, .rar, .zip, .jpg, .jpeg, .bmp, .tiff, .kum, .tlg, .sbx, .cr, .hse, .hsf, and .lhz. |
| T1218.011 Rundll32 |
GroupAPT28 | APT28 executed CHOPSTICK by using rundll32 commands such as |
| T1546.015 Component Object Model Hijacking |
GroupAPT28 | APT28 has used COM hijacking for persistence by replacing the legitimate |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareZebrocy | Zebrocy creates an entry in a Registry Run key for the malware to execute on startup. |
| T1555.003 Credentials from Web Browsers |
MalwareZebrocy | Zebrocy has the capability to upload dumper tools that extract credentials from web browsers and store them in database files. |
| T1573.001 Symmetric Cryptography |
GroupAPT28 | APT28 installed a Delphi backdoor that used a custom algorithm for C2 communications. |
| T1573.002 Asymmetric Cryptography |
MalwareZebrocy | Zebrocy uses SSL and AES ECB for encrypting C2 communications. |
| T1598.003 Spearphishing Link |
GroupAPT28 | APT28 has conducted credential phishing campaigns with links that redirect to credential harvesting sites. |
| T1680 Local Storage Discovery |
MalwareZebrocy | Zebrocy collects the serial number for the storage volume C:\. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.