ATT&CKReferencesMcAfee Netwire Mar 2015

McAfee Netwire Mar 2015

McAfee. (2015, March 2). Netwire RAT Behind Recent Targeted Attacks. Retrieved February 15, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1036.001
Invalid Code Signature
MalwareNETWIRE

The NETWIRE client has been signed by fake and invalid digital certificates.

T1056.001
Keylogging
MalwareNETWIRE

NETWIRE can perform keylogging.

T1082
System Information Discovery
MalwareNETWIRE

NETWIRE can discover and collect victim system information.

T1113
Screen Capture
MalwareNETWIRE

NETWIRE can capture the victim's screen.

T1547.001
Registry Run Keys / Startup Folder
MalwareNETWIRE

NETWIRE creates a Registry start-up entry to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.