US-CERT. (2017, November 22). Alert (TA17-318B): HIDDEN COBRA – North Korean Trojan: Volgmer. Retrieved December 7, 2017.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareVolgmer | Volgmer queries the system to identify existing services. |
| T1027.011 Fileless Storage |
MalwareVolgmer | Volgmer stores an encoded configuration file in |
| T1059.003 Windows Command Shell |
MalwareVolgmer | Volgmer can execute commands on the victim's machine. |
| T1082 System Information Discovery |
MalwareVolgmer | Volgmer can gather system information, the computer name, OS version, drive and serial information from the victim's machine. |
| T1083 File and Directory Discovery |
MalwareVolgmer | Volgmer can list directories on a victim. |
| T1105 Ingress Tool Transfer |
MalwareVolgmer | Volgmer can download remote files and additional payloads to the victim's machine. |
| T1543.003 Windows Service |
MalwareVolgmer | Volgmer installs a copy of itself in a randomly selected service, then overwrites the ServiceDLL entry in the service's Registry entry. Some Volgmer variants also install .dll files as services with names generated by a list of hard-coded strings. |
| T1573.002 Asymmetric Cryptography |
MalwareVolgmer | Some Volgmer variants use SSL to encrypt C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.