Hromcová, Z. (2018, June 07). InvisiMole: Surprisingly equipped spyware, undercover since 2013. Retrieved July 10, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareInvisiMole | InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP. |
| T1005 Data from Local System |
MalwareInvisiMole | InvisiMole can collect data from the system, and can monitor changes in specified directories. |
| T1007 System Service Discovery |
MalwareInvisiMole | InvisiMole can obtain running services on the victim. |
| T1008 Fallback Channels |
MalwareInvisiMole | InvisiMole has been configured with several servers available for alternate C2 communications. |
| T1010 Application Window Discovery |
MalwareInvisiMole | InvisiMole can enumerate windows and child windows on a compromised host. |
| T1012 Query Registry |
MalwareInvisiMole | InvisiMole can enumerate Registry values, keys, and data. |
| T1016 System Network Configuration Discovery |
MalwareInvisiMole | InvisiMole gathers information on the IP forwarding table, MAC address, configured proxy, and network SSID. |
| T1027 Obfuscated Files or Information |
MalwareInvisiMole | InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format. |
| T1033 System Owner/User Discovery |
MalwareInvisiMole | InvisiMole lists local users and session information. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareInvisiMole | InvisiMole has disguised its droppers as legitimate software or documents, matching their original names and locations, and saved its files as mpr.dll in the Windows folder. |
| T1057 Process Discovery |
MalwareInvisiMole | InvisiMole can obtain a list of running processes. |
| T1059.003 Windows Command Shell |
MalwareInvisiMole | InvisiMole can launch a remote shell to execute commands. |
| T1070.004 File Deletion |
MalwareInvisiMole | InvisiMole has deleted files and directories including XML and files successfully uploaded to C2 servers. |
| T1070.005 Network Share Connection Removal |
MalwareInvisiMole | InvisiMole can disconnect previously connected remote drives. |
| T1070.006 Timestomp |
MalwareInvisiMole | InvisiMole samples were timestomped by the authors by setting the PE timestamps to all zero values. InvisiMole also has a built-in command to modify file times. |
| T1071.001 Web Protocols |
MalwareInvisiMole | InvisiMole uses HTTP for C2 communications. |
| T1074.001 Local Data Staging |
MalwareInvisiMole | InvisiMole determines a working directory where it stores all the gathered data about the compromised machine. |
| T1082 System Information Discovery |
MalwareInvisiMole | InvisiMole can gather information on the OS version, computer name, DEP policy, and memory size. |
| T1083 File and Directory Discovery |
MalwareInvisiMole | InvisiMole can list information about files in a directory and recently opened or used documents. InvisiMole can also search for specific files by supplied file mask. |
| T1087.001 Local Account |
MalwareInvisiMole | InvisiMole has a command to list account information on the victim’s machine. |
| T1090.001 Internal Proxy |
MalwareInvisiMole | InvisiMole can function as a proxy to create a server that relays communication between the client and C&C server, or between two clients. |
| T1090.002 External Proxy |
MalwareInvisiMole | InvisiMole InvisiMole can identify proxy servers used by the victim and use them for C2 communication. |
| T1105 Ingress Tool Transfer |
MalwareInvisiMole | InvisiMole can upload files to the victim's machine for operations. |
| T1112 Modify Registry |
MalwareInvisiMole | InvisiMole has a command to create, set, copy, or delete a specified Registry key or value. |
| T1113 Screen Capture |
MalwareInvisiMole | InvisiMole can capture screenshots of not only the entire screen, but of each separate window open, in case they are overlapping. |
| T1119 Automated Collection |
MalwareInvisiMole | InvisiMole can sort and collect specific documents as well as generate a list of all files on a newly inserted drive and store them in an encrypted file. |
| T1123 Audio Capture |
MalwareInvisiMole | InvisiMole can record sound using input audio devices. |
| T1124 System Time Discovery |
MalwareInvisiMole | InvisiMole gathers the local system time from the victim’s machine. |
| T1125 Video Capture |
MalwareInvisiMole | InvisiMole can remotely activate the victim’s webcam to capture content. |
| T1135 Network Share Discovery |
MalwareInvisiMole | InvisiMole can gather network share information. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareInvisiMole | InvisiMole can decrypt, unpack and load a DLL from its resources, or from blobs encrypted with Data Protection API, two-key triple DES, and variations of the XOR cipher. |
| T1490 Inhibit System Recovery |
MalwareInvisiMole | InvisiMole can can remove all system restore points. |
| T1518 Software Discovery |
MalwareInvisiMole | InvisiMole can collect information about installed software used by specific users, software executed on user login, and software executed by each system. |
| T1548.002 Bypass User Account Control |
MalwareInvisiMole | InvisiMole can use fileless UAC bypass and create an elevated COM object to escalate privileges. |
| T1560.001 Archive via Utility |
MalwareInvisiMole | InvisiMole uses WinRAR to compress data that is intended to be exfiltrated. |
| T1560.002 Archive via Library |
MalwareInvisiMole | InvisiMole can use zlib to compress and decompress data. |
| T1560.003 Archive via Custom Method |
MalwareInvisiMole | InvisiMole uses a variation of the XOR cipher to encrypt files before exfiltration. |
| T1573.001 Symmetric Cryptography |
MalwareInvisiMole | InvisiMole uses variations of a simple XOR encryption routine for C&C communications. |
| T1574.001 DLL |
MalwareInvisiMole | InvisiMole can be launched by using DLL search order hijacking in which the wrapper DLL is placed in the same folder as explorer.exe and loaded during startup into the Windows Explorer process instead of the legitimate library. |
| T1680 Local Storage Discovery |
MalwareInvisiMole | InvisiMole can gather information on the mapped drives and system volume serial number. |
| T1686 Disable or Modify System Firewall |
MalwareInvisiMole | InvisiMole has a command to disable routing and the Firewall on the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.