Ray, V., Hayashi, K. (2016, February 29). New Malware ‘Rover’ Targets Indian Ambassador to Afghanistan. Retrieved February 29, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareRover | Rover searches for files on local drives based on a predefined list of file extensions. |
| T1020 Automated Exfiltration |
MalwareRover | Rover automatically searches for files on local drives based on a predefined list of file extensions and sends them to the command and control server every 60 minutes. Rover also automatically sends keylogger files and screenshots to the C2 server on a regular timeframe. |
| T1025 Data from Removable Media |
MalwareRover | Rover searches for files on attached removable drives based on a predefined list of file extensions every five seconds. |
| T1056.001 Keylogging |
MalwareRover | Rover has keylogging functionality. |
| T1074.001 Local Data Staging |
MalwareRover | Rover copies files from removable drives to |
| T1083 File and Directory Discovery |
MalwareRover | Rover automatically searches for files on local drives based on a predefined list of file extensions. |
| T1112 Modify Registry |
MalwareRover | Rover has functionality to remove Registry Run key persistence as a cleanup procedure. |
| T1113 Screen Capture |
MalwareRover | Rover takes screenshots of the compromised system's desktop and saves them to |
| T1119 Automated Collection |
MalwareRover | Rover automatically collects files from the local system and removable drives based on a predefined list of file extensions on a regular timeframe. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRover | Rover persists by creating a Registry entry in |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.