ATT&CKReferencesSymantec Daggerfly 2024

Symantec Daggerfly 2024

Threat Hunter Team. (2024, July 23). Daggerfly: Espionage Group Makes Major Update to Toolset. Retrieved July 25, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
MalwareNightdoor

Nightdoor uses scheduled tasks for persistence to load the final malware payload into memory.

T1059.003
Windows Command Shell
MalwareNightdoor

Nightdoor creates a cmd.exe shell to send and receive commands from the command and control server via open pipes.

T1071
Application Layer Protocol
MalwareNightdoor

Nightdoor uses TCP and UDP communication for command and control traffic.

T1102
Web Service
MalwareNightdoor

Nightdoor can utilize Microsoft OneDrive or Google Drive for command and control purposes.

T1140
Deobfuscate/Decode Files or Information
MalwareNightdoor

Nightdoor stores network configuration data in a file XOR encoded with the key value of `0x7A`.

T1497.001
System Checks
MalwareNightdoor

Nightdoor embeds code from the public `al-khaser` project, a repository that works to detect virtual machines, sandboxes, and malware analysis environments.

T1574
Hijack Execution Flow
MalwareNightdoor

Nightdoor uses a legitimate executable to load a malicious DLL file for installation.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.