Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
MalwareWhisperGate | WhisperGate can use PowerShell to support multiple actions including execution and defense evasion. |
| T1059.003 Windows Command Shell |
MalwareWhisperGate | WhisperGate can use `cmd.exe` to execute commands. |
| T1059.005 Visual Basic |
MalwareWhisperGate | WhisperGate can use a Visual Basic script to exclude the `C:\` drive from Windows Defender. |
| T1071.001 Web Protocols |
MalwareWhisperGate | WhisperGate can make an HTTPS connection to download additional files. |
| T1083 File and Directory Discovery |
MalwareWhisperGate | WhisperGate can locate files based on hardcoded file extensions. |
| T1102 Web Service |
MalwareWhisperGate | WhisperGate can download additional payloads hosted on a Discord channel. |
| T1105 Ingress Tool Transfer |
MalwareWhisperGate | WhisperGate can download additional stages of malware from a Discord CDN channel. |
| T1218.004 InstallUtil |
MalwareWhisperGate | WhisperGate has used `InstallUtil.exe` as part of its process to disable Windows Defender. |
| T1485 Data Destruction |
MalwareWhisperGate | WhisperGate can corrupt files by overwriting the first 1 MB with `0xcc` and appending random extensions. |
| T1497.001 System Checks |
MalwareWhisperGate | WhisperGate can stop its execution when it recognizes the presence of certain monitoring tools. |
| T1518.001 Security Software Discovery |
MalwareWhisperGate | WhisperGate can recognize the presence of monitoring tools on a target system. |
| T1561.002 Disk Structure Wipe |
MalwareWhisperGate | WhisperGate can overwrite the Master Book Record (MBR) on victim systems with a malicious 16-bit bootloader. |
| T1569.002 Service Execution |
MalwareWhisperGate | WhisperGate can download and execute AdvancedRun.exe via `sc.exe`. |
| T1685 Disable or Modify Tools |
MalwareWhisperGate | WhisperGate can download and execute AdvancedRun.exe to disable the Windows Defender Theat Protection service and set an exclusion path for the C:\ drive. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.