USG. (2020, May 12). MAR-10288834-2.v1 – North Korean Trojan: TAINTEDSCRIBE. Retrieved March 5, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE has used FakeTLS for session authentication. |
| T1008 Fallback Channels |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can randomly pick one of five hard-coded IP addresses for C2 communication; if one of the IP fails, it will wait 60 seconds and then try another IP address. |
| T1018 Remote System Discovery |
MalwareTAINTEDSCRIBE | The TAINTEDSCRIBE command and execution module can perform target system enumeration. |
| T1027.001 Binary Padding |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can execute |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTAINTEDSCRIBE | The TAINTEDSCRIBE main executable has disguised itself as Microsoft’s Narrator. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupLazarus Group | Lazarus Group has renamed malicious code to disguise it as Microsoft's narrator and other legitimate files. |
| T1057 Process Discovery |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can execute |
| T1059.003 Windows Command Shell |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can enable Windows CLI access and execute files. |
| T1070.004 File Deletion |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can delete files from a compromised host. |
| T1070.006 Timestomp |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can change the timestamp of specified filenames. |
| T1083 File and Directory Discovery |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can use |
| T1105 Ingress Tool Transfer |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can download additional modules from its C2 server. |
| T1124 System Time Discovery |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can execute |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can copy itself into the current user’s Startup folder as “Narrator.exe” for persistence. |
| T1560 Archive Collected Data |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE has used |
| T1573.001 Symmetric Cryptography |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE uses a Linear Feedback Shift Register (LFSR) algorithm for network encryption. |
| T1680 Local Storage Discovery |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can use |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.