Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareClambling | Clambling can collect information from a compromised host. |
| T1005 Data from Local System |
MalwareRCSession | RCSession can collect data from a compromised host. |
| T1012 Query Registry |
MalwareClambling | Clambling has the ability to enumerate Registry keys, including |
| T1016 System Network Configuration Discovery |
MalwareClambling | Clambling can enumerate the IP address of a compromised machine. |
| T1027 Obfuscated Files or Information |
MalwarePlugX | PlugX can use API hashing and modify the names of strings to evade detection. |
| T1027 Obfuscated Files or Information |
MalwareClambling | The Clambling executable has been obfuscated when dropped on a compromised host. |
| T1027.002 Software Packing |
GroupThreat Group-3390 | Threat Group-3390 has packed malware and tools, including using VMProtect. |
| T1027.011 Fileless Storage |
MalwareRCSession | RCSession can store its obfuscated configuration file in the Registry under `HKLM\SOFTWARE\Plus` or `HKCU\SOFTWARE\Plus`. |
| T1027.013 Encrypted/Encoded File |
MalwareHyperBro | HyperBro can be delivered encrypted to a compromised host. |
| T1027.015 Compression |
MalwareRCSession | RCSession can compress and obfuscate its strings to evade detection on a compromised host. |
| T1033 System Owner/User Discovery |
GroupThreat Group-3390 | Threat Group-3390 has used `whoami` to collect system user information. |
| T1033 System Owner/User Discovery |
MalwareClambling | Clambling can identify the username on a compromised host. |
| T1036 Masquerading |
MalwareRCSession | RCSession has used a file named English.rtf to appear benign on victim hosts. |
| T1055 Process Injection |
MalwareClambling | Clambling can inject into the `svchost.exe` process for execution. |
| T1055.012 Process Hollowing |
MalwareRCSession | RCSession can launch itself from a hollowed svchost.exe process. |
| T1055.012 Process Hollowing |
MalwareClambling | Clambling can execute binaries through process hollowing. |
| T1056.001 Keylogging |
MalwareRCSession | RCSession has the ability to capture keystrokes on a compromised host. |
| T1056.001 Keylogging |
MalwareClambling | Clambling can capture keystrokes on a compromised host. |
| T1057 Process Discovery |
MalwareClambling | Clambling can enumerate processes on a targeted system. |
| T1059.001 PowerShell |
MalwareClambling | The Clambling dropper can use PowerShell to download the malware. |
| T1059.001 PowerShell |
GroupThreat Group-3390 | Threat Group-3390 has used PowerShell for execution. |
| T1059.003 Windows Command Shell |
MalwareRCSession | RCSession can use `cmd.exe` for execution on compromised hosts. |
| T1059.003 Windows Command Shell |
MalwareClambling | Clambling can use cmd.exe for command execution. |
| T1070.004 File Deletion |
GroupThreat Group-3390 | Threat Group-3390 has deleted existing logs and exfiltrated file archives from a victim. |
| T1071 Application Layer Protocol |
MalwareClambling | Clambling has the ability to use Telnet for communication. |
| T1071.001 Web Protocols |
MalwareClambling | Clambling has the ability to communicate over HTTP. |
| T1071.001 Web Protocols |
MalwareRCSession | RCSession can use HTTP in C2 communications. |
| T1082 System Information Discovery |
MalwareClambling | Clambling can discover the hostname, computer name, and Windows version of a targeted machine. |
| T1083 File and Directory Discovery |
MalwareClambling | Clambling can browse directories on a compromised host. |
| T1095 Non-Application Layer Protocol |
MalwareRCSession | RCSession has the ability to use TCP and UDP in C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareClambling | Clambling has the ability to use TCP and UDP for communication. |
| T1102.002 Bidirectional Communication |
MalwareClambling | Clambling can use Dropbox to download malicious payloads, send commands, and receive information. |
| T1105 Ingress Tool Transfer |
GroupThreat Group-3390 | Threat Group-3390 has downloaded additional malware and tools, including through the use of `certutil`, onto a compromised host . |
| T1112 Modify Registry |
MalwareClambling | Clambling can set and delete Registry keys. |
| T1112 Modify Registry |
MalwareRCSession | RCSession can write its configuration file to the Registry. |
| T1113 Screen Capture |
MalwareClambling | Clambling has the ability to capture screenshots. |
| T1115 Clipboard Data |
MalwareClambling | Clambling has the ability to capture and store clipboard data. |
| T1124 System Time Discovery |
MalwareClambling | Clambling can determine the current time. |
| T1125 Video Capture |
MalwareClambling | Clambling can record screen content in AVI format. |
| T1135 Network Share Discovery |
MalwareClambling | Clambling has the ability to enumerate network shares. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareClambling | Clambling can deobfuscate its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePlugX | PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHyperBro | HyperBro can unpack and decrypt its payload prior to execution. |
| T1204.002 Malicious File |
GroupThreat Group-3390 | Threat Group-3390 has lured victims into opening malicious files containing malware. |
| T1204.002 Malicious File |
MalwareClambling | Clambling has gained execution through luring victims into opening malicious files. |
| T1497.003 Time Based Checks |
MalwareClambling | Clambling can wait 30 minutes before initiating contact with C2. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareClambling | Clambling can establish persistence by adding a Registry run key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRCSession | RCSession has the ability to modify a Registry Run key to establish persistence. |
| T1548.002 Bypass User Account Control |
MalwareClambling | Clambling has the ability to bypass UAC using a `passuac.dll` file. |
| T1548.002 Bypass User Account Control |
MalwareRCSession | RCSession can bypass UAC to escalate privileges. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.