Falcone, R. and Miller-Osborn, J.. (2015, December 18). Attack on French Diplomat Linked to Operation Lotus Blossom. Retrieved February 15, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareEmissary | Variants of Emissary encrypt payloads using various XOR ciphers, as well as a custom algorithm that uses the "srand" and "rand" functions. |
| T1055.001 Dynamic-link Library Injection |
MalwareEmissary | Emissary injects its DLL file into a newly spawned Internet Explorer process. |
| T1059.003 Windows Command Shell |
MalwareEmissary | Emissary has the capability to create a remote shell and execute specified commands. |
| T1071.001 Web Protocols |
MalwareEmissary | Emissary uses HTTP or HTTPS for C2. |
| T1105 Ingress Tool Transfer |
MalwareEmissary | Emissary has the capability to download files from the C2 server. |
| T1573.001 Symmetric Cryptography |
MalwareEmissary | The C2 server response to a beacon sent by a variant of Emissary contains a 36-character GUID value that is used as an encryption key for subsequent network communications. Some variants of Emissary use various XOR operations to encrypt C2 data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.