Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareElise | Elise executes |
| T1055.001 Dynamic-link Library Injection |
MalwareElise | Elise injects DLL files into iexplore.exe. |
| T1057 Process Discovery |
MalwareElise | Elise enumerates processes via the |
| T1070.004 File Deletion |
MalwareElise | Elise is capable of launching a remote shell on the host to delete itself. |
| T1074.001 Local Data Staging |
MalwareElise | Elise creates a file in |
| T1083 File and Directory Discovery |
MalwareElise | A variant of Elise executes |
| T1105 Ingress Tool Transfer |
MalwareElise | Elise can download additional files from the C2 server for execution. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareElise | If establishing persistence by installation as a new service fails, one variant of Elise establishes persistence for the created .exe file by setting the following Registry key: |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.