ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareMetamorfo | Metamorfo has encrypted payloads and strings. |
| T1033 System Owner/User Discovery |
MalwareMetamorfo | Metamorfo has collected the username from the victim's machine. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMetamorfo | Metamorfo has disguised an MSI file as the Adobe Acrobat Reader Installer and has masqueraded payloads as OneDrive, WhatsApp, or Spotify, for example. |
| T1041 Exfiltration Over C2 Channel |
MalwareMetamorfo | Metamorfo can send the data it collects to the C2 server. |
| T1056.001 Keylogging |
MalwareMetamorfo | Metamorfo has a command to launch a keylogger and capture keystrokes on the victim’s machine. |
| T1071.001 Web Protocols |
MalwareMetamorfo | Metamorfo has used HTTP for C2. |
| T1082 System Information Discovery |
MalwareMetamorfo | Metamorfo has collected the hostname and operating system version from the compromised host. |
| T1102.001 Dead Drop Resolver |
MalwareMetamorfo | Metamorfo has used YouTube to store and hide C&C server domains. |
| T1105 Ingress Tool Transfer |
MalwareMetamorfo | Metamorfo has used MSI files to download additional files to execute. |
| T1112 Modify Registry |
MalwareMetamorfo | Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key. |
| T1113 Screen Capture |
MalwareMetamorfo | Metamorfo can collect screenshots of the victim’s machine. |
| T1115 Clipboard Data |
MalwareMetamorfo | Metamorfo has a function to hijack data from the clipboard by monitoring the contents of the clipboard and replacing the cryptocurrency wallet with the attacker's. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMetamorfo | Upon execution, Metamorfo has unzipped itself after being downloaded to the system and has performed string decryption. |
| T1204.002 Malicious File |
MalwareMetamorfo | Metamorfo requires the user to double-click the executable to run the malicious HTA file or to download a malicious installer. |
| T1218.007 Msiexec |
MalwareMetamorfo | Metamorfo has used MsiExec.exe to automatically execute files. |
| T1518 Software Discovery |
MalwareMetamorfo | Metamorfo has searched the compromised system for banking applications. |
| T1518.001 Security Software Discovery |
MalwareMetamorfo | Metamorfo collects a list of installed antivirus software from the victim’s system. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMetamorfo | Metamorfo has configured persistence to the Registry key |
| T1565.002 Transmitted Data Manipulation |
MalwareMetamorfo | Metamorfo has a function that can watch the contents of the system clipboard for valid bitcoin addresses, which it then overwrites with the attacker's address. |
| T1566.001 Spearphishing Attachment |
MalwareMetamorfo | Metamorfo has been delivered to victims via emails with malicious HTML attachments. |
| T1573.001 Symmetric Cryptography |
MalwareMetamorfo | Metamorfo has encrypted C2 commands with AES-256. |
| T1574.001 DLL |
MalwareMetamorfo | Metamorfo has side-loaded its malicious DLL file. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.