ATT&CKReferencesSymantec Dyre June 2015

Symantec Dyre June 2015

Symantec Security Response. (2015, June 23). Dyre: Emerging threat on financial fraud landscape. Retrieved August 23, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1055.001
Dynamic-link Library Injection
MalwareDyre

Dyre injects into other processes to load modules.

T1071.001
Web Protocols
MalwareDyre

Dyre uses HTTPS for C2 communications.

T1105
Ingress Tool Transfer
MalwareDyre

Dyre has a command to download and executes additional files.

T1140
Deobfuscate/Decode Files or Information
MalwareDyre

Dyre decrypts resources needed for targeting the victim.

T1497.001
System Checks
MalwareDyre

Dyre can detect sandbox analysis environments by inspecting the process list and Registry.

T1543.003
Windows Service
MalwareDyre

Dyre registers itself as a service by adding several Registry keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.