Threat Hunter Team. (2024, July 23). Daggerfly: Espionage Group Makes Major Update to Toolset. Retrieved July 25, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1053.005 Scheduled Task |
MalwareNightdoor | Nightdoor uses scheduled tasks for persistence to load the final malware payload into memory. |
| T1059.003 Windows Command Shell |
MalwareNightdoor | Nightdoor creates a cmd.exe shell to send and receive commands from the command and control server via open pipes. |
| T1071 Application Layer Protocol |
MalwareNightdoor | Nightdoor uses TCP and UDP communication for command and control traffic. |
| T1102 Web Service |
MalwareNightdoor | Nightdoor can utilize Microsoft OneDrive or Google Drive for command and control purposes. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNightdoor | Nightdoor stores network configuration data in a file XOR encoded with the key value of `0x7A`. |
| T1497.001 System Checks |
MalwareNightdoor | Nightdoor embeds code from the public `al-khaser` project, a repository that works to detect virtual machines, sandboxes, and malware analysis environments. |
| T1574 Hijack Execution Flow |
MalwareNightdoor | Nightdoor uses a legitimate executable to load a malicious DLL file for installation. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.