Yamout, M. (2021, November 29). WIRTE’s campaign in the Middle East ‘living off the land’ since at least 2019. Retrieved February 1, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareLitePower | LitePower can query the Registry for keys added to execute COM hijacking. |
| T1033 System Owner/User Discovery |
MalwareLitePower | LitePower can determine if the current user has admin privileges. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupWIRTE | WIRTE has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate. |
| T1041 Exfiltration Over C2 Channel |
MalwareLitePower | LitePower can send collected data, including screenshots, over its C2 channel. |
| T1053.005 Scheduled Task |
MalwareLitePower | LitePower can create a scheduled task to enable persistence mechanisms. |
| T1059.001 PowerShell |
MalwareLitePower | LitePower can use a PowerShell script to execute commands. |
| T1059.001 PowerShell |
MalwareFerocious | Ferocious can use PowerShell scripts for execution. |
| T1059.005 Visual Basic |
MalwareFerocious | Ferocious has the ability to use Visual Basic scripts for execution. |
| T1070.004 File Deletion |
MalwareFerocious | Ferocious can delete files from a compromised host. |
| T1071.001 Web Protocols |
MalwareLitePower | LitePower can use HTTP and HTTPS for C2 communications. |
| T1082 System Information Discovery |
MalwareFerocious | Ferocious can use |
| T1082 System Information Discovery |
MalwareLitePower | LitePower has the ability to enumerate the OS architecture. |
| T1105 Ingress Tool Transfer |
MalwareLitePower | LitePower has the ability to download payloads containing system commands to a compromised host. |
| T1106 Native API |
MalwareLitePower | LitePower can use various API calls. |
| T1112 Modify Registry |
MalwareFerocious | Ferocious has the ability to add a Class ID in the current user Registry hive to enable persistence mechanisms. |
| T1113 Screen Capture |
MalwareLitePower | LitePower can take system screenshots and save them to `%AppData%`. |
| T1120 Peripheral Device Discovery |
MalwareFerocious | Ferocious can run |
| T1204.002 Malicious File |
GroupWIRTE | WIRTE has attempted to lure users into opening malicious documents including MS Word and Excel files, at times using a decoy document to encourage execution of malicious payloads. |
| T1497.001 System Checks |
MalwareFerocious | Ferocious can run anti-sandbox checks using the Microsoft Excel 4.0 function |
| T1518.001 Security Software Discovery |
MalwareLitePower | LitePower can identify installed AV software. |
| T1518.001 Security Software Discovery |
MalwareFerocious | Ferocious has checked for AV software as part of its persistence process. |
| T1546.015 Component Object Model Hijacking |
MalwareFerocious | Ferocious can use COM hijacking to establish persistence. |
| T1566.001 Spearphishing Attachment |
GroupWIRTE | WIRTE has sent emails to intended victims with malicious MS Word and Excel attachments. |
| T1571 Non-Standard Port |
GroupWIRTE | WIRTE has used HTTPS over ports 2083 and 2087 for C2. |
| T1680 Local Storage Discovery |
MalwareLitePower | LitePower has the ability to list local drives. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.