ATT&CKReferencesCitizenLab KeyBoy Nov 2016

CitizenLab KeyBoy Nov 2016

Hulcoop, A., et al. (2016, November 17). It’s Parliamentary KeyBoy and the targeting of the Tibetan Community. Retrieved June 13, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareKeyBoy

In one version of KeyBoy, string obfuscation routines were used to hide many of the critical values referenced in the malware.

T1059.005
Visual Basic
MalwareKeyBoy

KeyBoy uses VBS scripts for installing files and performing execution.

T1059.006
Python
MalwareKeyBoy

KeyBoy uses Python scripts for installing files and performing execution.

T1547.004
Winlogon Helper DLL
MalwareKeyBoy

KeyBoy issues the command reg add “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon” to achieve persistence.

T1574.001
DLL
GroupTropic Trooper

Tropic Trooper has been known to side-load DLLs using a valid version of a Windows Address Book and Windows Defender executable with one of their tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.