Parys, B. (2017, February 11). The KeyBoys are back in town. Retrieved June 13, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareKeyBoy | KeyBoy uses custom SSL libraries to impersonate SSL in C2 traffic. |
| T1016 System Network Configuration Discovery |
MalwareKeyBoy | KeyBoy can determine the public or WAN IP address for the system. |
| T1059.001 PowerShell |
MalwareKeyBoy | KeyBoy uses PowerShell commands to download and execute payloads. |
| T1059.003 Windows Command Shell |
MalwareKeyBoy | KeyBoy can launch interactive shells for communicating with the victim machine. |
| T1070.006 Timestomp |
MalwareKeyBoy | KeyBoy time-stomped its DLL in order to evade detection. |
| T1082 System Information Discovery |
MalwareKeyBoy | KeyBoy can gather extended system information, such as information about the operating system and memory. |
| T1083 File and Directory Discovery |
MalwareKeyBoy | KeyBoy has a command to launch a file browser or explorer on the system. |
| T1105 Ingress Tool Transfer |
MalwareKeyBoy | KeyBoy has a download and upload functionality. |
| T1113 Screen Capture |
MalwareKeyBoy | KeyBoy has a command to perform screen grabbing. |
| T1543.003 Windows Service |
GroupTropic Trooper | Tropic Trooper has installed a service pointing to a malicious DLL dropped to disk. |
| T1547.004 Winlogon Helper DLL |
MalwareKeyBoy | KeyBoy issues the command |
| T1559.002 Dynamic Data Exchange |
MalwareKeyBoy | KeyBoy uses the Dynamic Data Exchange (DDE) protocol to download remote payloads. |
| T1564.003 Hidden Window |
MalwareKeyBoy | KeyBoy uses |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.