Facundo Muñoz. (2023, April 26). Evasive Panda APT group delivers malware via updates for popular Chinese software. Retrieved July 25, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareMgBot | MgBot includes modules for collecting files from local systems based on a given set of properties and filenames. |
| T1025 Data from Removable Media |
MalwareMgBot | MgBot includes modules capable of gathering information from USB thumb drives and CD-ROMs on the victim machine given a list of provided criteria. |
| T1056.001 Keylogging |
MalwareMgBot | MgBot includes keylogger payloads focused on the QQ chat application. |
| T1115 Clipboard Data |
MalwareMgBot | MgBot can capture clipboard data. |
| T1123 Audio Capture |
MalwareMgBot | MgBot can capture input and output audio streams from infected devices. |
| T1195.002 Compromise Software Supply Chain |
GroupDaggerfly | Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims. |
| T1213.006 Databases |
MalwareMgBot | MgBot includes a module capable of stealing content from the Tencent QQ database storing user QQ message history on infected devices. |
| T1539 Steal Web Session Cookie |
MalwareMgBot | MgBot includes modules that can steal cookies from Firefox, Chrome, and Edge web browsers. |
| T1555 Credentials from Password Stores |
MalwareMgBot | MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software. |
| T1555.003 Credentials from Web Browsers |
MalwareMgBot | MgBot includes modules for stealing credentials from various browsers and applications, including Chrome, Opera, Firefox, Foxmail, QQBrowser, FileZilla, and WinSCP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.