ATT&CKReferencesCopyKittens Nov 2015

CopyKittens Nov 2015

Minerva Labs LTD and ClearSky Cyber Security. (2015, November 23). CopyKittens Attack Group. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareMatryoshka

Matryoshka obfuscates API function names using a substitute cipher combined with Base64 encoding.

T1053.005
Scheduled Task
MalwareMatryoshka

Matryoshka can establish persistence by adding a Scheduled Task named "Microsoft Boost Kernel Optimization".

T1055.001
Dynamic-link Library Injection
MalwareMatryoshka

Matryoshka uses reflective DLL injection to inject the malicious library and execute the RAT.

T1056.001
Keylogging
MalwareMatryoshka

Matryoshka is capable of keylogging.

T1071.004
DNS
MalwareMatryoshka

Matryoshka uses DNS for C2.

T1113
Screen Capture
MalwareMatryoshka

Matryoshka is capable of performing screen captures.

T1218.011
Rundll32
MalwareMatryoshka

Matryoshka uses rundll32.exe in a Registry Run key value for execution as part of its persistence mechanism.

T1547.001
Registry Run Keys / Startup Folder
MalwareMatryoshka

Matryoshka can establish persistence by adding Registry Run keys.

T1555
Credentials from Password Stores
MalwareMatryoshka

Matryoshka is capable of stealing Outlook passwords.

T1560.003
Archive via Custom Method
GroupCopyKittens

CopyKittens encrypts data with a substitute cipher prior to exfiltration.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.