ATT&CKReferencesJPCert BlackTech Malware September 2019

JPCert BlackTech Malware September 2019

Tomonaga, S.. (2019, September 18). Malware Used by BlackTech after Network Intrusion. Retrieved May 6, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1055
Process Injection
MalwareTSCookie

TSCookie has the ability to inject code into the svchost.exe, iexplorer.exe, explorer.exe, and default browser processes.

T1071.001
Web Protocols
MalwareTSCookie

TSCookie can multiple protocols including HTTP and HTTPS in communication with command and control (C2) servers.

T1090
Proxy
MalwareTSCookie

TSCookie has the ability to proxy communications with command and control (C2) servers.

T1095
Non-Application Layer Protocol
MalwareTSCookie

TSCookie can use ICMP to receive information on the destination server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.