Carr, N, et all. (2019, October 10). Mahalo FIN7: Responding to the Criminal Operators’ New Tools and Techniques. Retrieved October 11, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareBOOSTWRITE | BOOSTWRITE has encoded its payloads using a ChaCha stream cipher with a 256-bit key and 64-bit Initialization vector (IV) to evade detection. |
| T1056.004 Credential API Hooking |
MalwareRDFSNIFFER | RDFSNIFFER hooks several Win32 API functions to hijack elements of the remote system management user-interface. |
| T1070.004 File Deletion |
MalwareRDFSNIFFER | RDFSNIFFER has the capability of deleting local files. |
| T1106 Native API |
MalwareRDFSNIFFER | RDFSNIFFER has used several Win32 API functions to interact with the victim machine. |
| T1129 Shared Modules |
MalwareBOOSTWRITE | BOOSTWRITE has used the DWriteCreateFactory() function to load additional modules. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBOOSTWRITE | BOOSTWRITE has used a a 32-byte long multi-XOR key to decode data inside its payload. |
| T1553.002 Code Signing |
MalwareBOOSTWRITE | BOOSTWRITE has been signed by a valid CA. |
| T1574.001 DLL |
MalwareBOOSTWRITE | BOOSTWRITE has exploited the loading of the legitimate Dwrite.dll file by actually loading the gdi library, which then loads the gdiplus library and ultimately loads the local Dwrite dll. |
| T1587.001 Malware |
GroupFIN7 | FIN7 has developed malware for use in operations, including the creation of infected removable media. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.