ATT&CKReferencesKaspersky Regin

Kaspersky Regin

Kaspersky Lab's Global Research and Analysis Team. (2014, November 24). THE REGIN PLATFORM NATION-STATE OWNAGE OF GSM NETWORKS. Retrieved December 1, 2014.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
MalwareRegin

The Regin malware platform can use Windows admin shares to move laterally.

T1036.001
Invalid Code Signature
MalwareRegin

Regin stage 1 modules for 64-bit systems have been found to be signed with fake certificates masquerading as originating from Microsoft Corporation and Broadcom Corporation.

T1040
Network Sniffing
MalwareRegin

Regin appears to have functionality to sniff for credentials passed over HTTP, SMTP, and SMB.

T1056.001
Keylogging
MalwareRegin

Regin contains a keylogger.

T1071.001
Web Protocols
MalwareRegin

The Regin malware platform supports many standard protocols, including HTTP and HTTPS.

T1071.002
File Transfer Protocols
MalwareRegin

The Regin malware platform supports many standard protocols, including SMB.

T1090.002
External Proxy
MalwareRegin

Regin leveraged several compromised universities as proxies to obscure its origin.

T1095
Non-Application Layer Protocol
MalwareRegin

The Regin malware platform can use ICMP to communicate between infected computers.

T1112
Modify Registry
MalwareRegin

Regin appears to have functionality to modify remote Registry information.

T1564.004
NTFS File Attributes
MalwareRegin

The Regin malware platform uses Extended Attributes to store encrypted executables.

T1564.005
Hidden File System
MalwareRegin

Regin has used a hidden file system to store some of its components.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.