ATT&CKReferencesTelefonica Snip3 December 2021

Telefonica Snip3 December 2021

Jornet, A. (2021, December 23). Snip3, an investigation into malware. Retrieved September 19, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
ToolAsyncRAT

AsyncRAT can check if the current user of a compromised system is an administrator.

T1053.005
Scheduled Task
ToolAsyncRAT

AsyncRAT can create a scheduled task to maintain persistence on system start-up.

T1055.012
Process Hollowing
MalwareSnip3

Snip3 can use RunPE to execute malicious payloads within a hollowed Windows process.

T1057
Process Discovery
ToolAsyncRAT

AsyncRAT can examine running processes to determine if a debugger is present.

T1059.001
PowerShell
MalwareSnip3

Snip3 can use a PowerShell script for second-stage execution.

T1059.005
Visual Basic
MalwareSnip3

Snip3 can use visual basic scripts for first-stage execution.

T1104
Multi-Stage Channels
MalwareSnip3

Snip3 can download and execute additional payloads and modules over separate communication channels.

T1105
Ingress Tool Transfer
MalwareSnip3

Snip3 can download additional payloads to compromised systems.

T1106
Native API
ToolAsyncRAT

AsyncRAT has the ability to use OS APIs including `CheckRemoteDebuggerPresent`.

T1189
Drive-by Compromise
MalwareSnip3

Snip3 has been delivered to targets via downloads from malicious domains.

T1204.001
Malicious Link
MalwareSnip3

Snip3 has been executed through luring victims into clicking malicious links.

T1204.002
Malicious File
GroupTA2541

TA2541 has used macro-enabled MS Word documents to lure victims into executing malicious payloads.

T1204.002
Malicious File
MalwareSnip3

Snip3 can gain execution through the download of visual basic files.

T1497.001
System Checks
ToolAsyncRAT

AsyncRAT can identify strings such as Virtual, vmware, or VirtualBox to detect virtualized environments.

T1547.001
Registry Run Keys / Startup Folder
MalwareSnip3

Snip3 can create a VBS file in startup to persist after system restarts.

T1564.003
Hidden Window
ToolAsyncRAT

AsyncRAT can hide the execution of scheduled tasks using `ProcessWindowStyle.Hidden`.

T1566.001
Spearphishing Attachment
MalwareSnip3

Snip3 has been delivered to victims through malicious e-mail attachments.

T1566.002
Spearphishing Link
MalwareSnip3

Snip3 has been delivered to victims through e-mail links to malicious files.

T1566.002
Spearphishing Link
GroupTA2541

TA2541 has used spearphishing e-mails with malicious links to deliver malware.

T1622
Debugger Evasion
ToolAsyncRAT

AsyncRAT can use the `CheckRemoteDebuggerPresent` function to detect the presence of a debugger.

T1680
Local Storage Discovery
ToolAsyncRAT

AsyncRAT can check the disk size through the values obtained with `DeviceInfo.`

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.