Cherepanov, A.. (2016, May 17). Operation Groundbait: Analysis of a surveillance toolkit. Retrieved May 18, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwarePrikormka | A module in Prikormka collects information from the victim about its IP addresses and MAC addresses. |
| T1025 Data from Removable Media |
MalwarePrikormka | Prikormka contains a module that collects documents with certain extensions from removable media or fixed drives connected via USB. |
| T1027.013 Encrypted/Encoded File |
MalwarePrikormka | Some resources in Prikormka are encrypted with a simple XOR operation or encoded with Base64. |
| T1033 System Owner/User Discovery |
MalwarePrikormka | A module in Prikormka collects information from the victim about the current user name. |
| T1056.001 Keylogging |
MalwarePrikormka | Prikormka contains a keylogger module that collects keystrokes and the titles of foreground windows. |
| T1070.004 File Deletion |
MalwarePrikormka | After encrypting its own log files, the log encryption module in Prikormka deletes the original, unencrypted files from the host. |
| T1074.001 Local Data Staging |
MalwarePrikormka | Prikormka creates a directory, |
| T1082 System Information Discovery |
MalwarePrikormka | A module in Prikormka collects information from the victim about Windows OS version, computer name, battery info, and physical memory. |
| T1083 File and Directory Discovery |
MalwarePrikormka | A module in Prikormka collects information about the paths, size, and creation time of files with specific file extensions, but not the actual content of the file. |
| T1113 Screen Capture |
MalwarePrikormka | Prikormka contains a module that captures screenshots of the victim's desktop. |
| T1120 Peripheral Device Discovery |
MalwarePrikormka | A module in Prikormka collects information on available printers and disk drives. |
| T1132.001 Standard Encoding |
MalwarePrikormka | Prikormka encodes C2 traffic with Base64. |
| T1218.011 Rundll32 |
MalwarePrikormka | Prikormka uses rundll32.exe to load its DLL. |
| T1518.001 Security Software Discovery |
MalwarePrikormka | A module in Prikormka collects information from the victim about installed anti-virus software. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePrikormka | Prikormka adds itself to a Registry Run key with the name guidVGA or guidVSA. |
| T1555 Credentials from Password Stores |
MalwarePrikormka | A module in Prikormka collects passwords stored in applications installed on the victim. |
| T1555.003 Credentials from Web Browsers |
MalwarePrikormka | A module in Prikormka gathers logins and passwords stored in applications on the victims, including Google Chrome, Mozilla Firefox, and several other browsers. |
| T1560 Archive Collected Data |
MalwarePrikormka | After collecting documents from removable media, Prikormka compresses the collected files, and encrypts it with Blowfish. |
| T1573.001 Symmetric Cryptography |
MalwarePrikormka | Prikormka encrypts some C2 traffic with the Blowfish cipher. |
| T1574.001 DLL |
MalwarePrikormka | Prikormka uses DLL search order hijacking for persistence by saving itself as ntshrui.dll to the Windows directory so it will load before the legitimate ntshrui.dll saved in the System32 subdirectory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.