US-CERT. (2018, August 09). MAR-10135536-17 – North Korean Trojan: KEYMARBLE. Retrieved August 16, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareKEYMARBLE | KEYMARBLE gathers the MAC address of the victim’s machine. |
| T1057 Process Discovery |
MalwareKEYMARBLE | KEYMARBLE can obtain a list of running processes on the system. |
| T1059.003 Windows Command Shell |
MalwareKEYMARBLE | KEYMARBLE can execute shell commands using cmd.exe. |
| T1070.004 File Deletion |
MalwareKEYMARBLE | KEYMARBLE has the capability to delete files off the victim’s machine. |
| T1082 System Information Discovery |
MalwareKEYMARBLE | KEYMARBLE has the capability to collect the computer name, language settings, the OS version, CPU information, and time elapsed since system start. |
| T1083 File and Directory Discovery |
MalwareKEYMARBLE | KEYMARBLE has a command to search for files on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareKEYMARBLE | KEYMARBLE can upload files to the victim’s machine and can download additional payloads. |
| T1112 Modify Registry |
MalwareKEYMARBLE | KEYMARBLE has a command to create Registry entries for storing data under |
| T1113 Screen Capture |
MalwareKEYMARBLE | KEYMARBLE can capture screenshots of the victim’s machine. |
| T1573.001 Symmetric Cryptography |
MalwareKEYMARBLE | KEYMARBLE uses a customized XOR algorithm to encrypt C2 communications. |
| T1680 Local Storage Discovery |
MalwareKEYMARBLE | KEYMARBLE has the capability to collect information on disk devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.