Knight, S.. (2020, April 16). VMware Carbon Black TAU Threat Analysis: The Evolution of Lazarus. Retrieved May 1, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareHotCroissant | HotCroissant has the ability to retrieve a list of services on the infected host. |
| T1010 Application Window Discovery |
MalwareHotCroissant | HotCroissant has the ability to list the names of all open windows on the infected host. |
| T1016 System Network Configuration Discovery |
MalwareRifdoor | Rifdoor has the ability to identify the IP address of the compromised host. |
| T1027.001 Binary Padding |
MalwareRifdoor | Rifdoor has added four additional bytes of data upon launching, then saved the changed version as |
| T1027.002 Software Packing |
MalwareHotCroissant | HotCroissant has used the open source UPX executable packer. |
| T1027.013 Encrypted/Encoded File |
MalwareRifdoor | Rifdoor has encrypted strings with a single byte XOR algorithm. |
| T1027.013 Encrypted/Encoded File |
MalwareHotCroissant | HotCroissant has encrypted strings with single-byte XOR and base64 encoded RC4. |
| T1033 System Owner/User Discovery |
MalwareRifdoor | Rifdoor has the ability to identify the username on the compromised host. |
| T1033 System Owner/User Discovery |
MalwareHotCroissant | HotCroissant has the ability to collect the username on the infected host. |
| T1041 Exfiltration Over C2 Channel |
MalwareHotCroissant | HotCroissant has the ability to download files from the infected host to the command and control (C2) server. |
| T1053.005 Scheduled Task |
MalwareHotCroissant | HotCroissant has attempted to install a scheduled task named “Java Maintenance64” on startup to establish persistence. |
| T1057 Process Discovery |
MalwareHotCroissant | HotCroissant has the ability to list running processes on the infected host. |
| T1059.003 Windows Command Shell |
MalwareHotCroissant | HotCroissant can remotely open applications on the infected host with the |
| T1070.004 File Deletion |
MalwareHotCroissant | HotCroissant has the ability to clean up installed files, delete files, and delete itself from the victim’s machine. |
| T1082 System Information Discovery |
MalwareRifdoor | Rifdoor has the ability to identify the Windows version on the compromised host. |
| T1083 File and Directory Discovery |
MalwareHotCroissant | HotCroissant has the ability to retrieve a list of files in a given directory as well as drives and drive types. |
| T1105 Ingress Tool Transfer |
MalwareHotCroissant | HotCroissant has the ability to upload a file from the command and control (C2) server to the victim machine. |
| T1113 Screen Capture |
MalwareHotCroissant | HotCroissant has the ability to do real time screen viewing on an infected host. |
| T1204.002 Malicious File |
MalwareRifdoor | Rifdoor has been executed from malicious Excel or Word documents containing macros. |
| T1489 Service Stop |
MalwareHotCroissant | HotCroissant has the ability to stop services on the infected host. |
| T1518 Software Discovery |
MalwareHotCroissant | HotCroissant can retrieve a list of applications from the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRifdoor | Rifdoor has created a new registry entry at |
| T1564.003 Hidden Window |
MalwareHotCroissant | HotCroissant has the ability to hide the window for operations performed on a given file. |
| T1566.001 Spearphishing Attachment |
MalwareRifdoor | Rifdoor has been distributed in e-mails with malicious Excel or Word documents. |
| T1573.001 Symmetric Cryptography |
MalwareHotCroissant | HotCroissant has compressed network communications and encrypted them with a custom stream cipher. |
| T1573.001 Symmetric Cryptography |
MalwareRifdoor | Rifdoor has encrypted command and control (C2) communications with a stream cipher. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.