Secureworks. (2019, July 24). Updated Karagany Malware Targets Energy Sector. Retrieved August 12, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can monitor the titles of open windows to identify specific keywords. |
| T1016 System Network Configuration Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can gather information on the network configuration of a compromised host. |
| T1027 Obfuscated Files or Information |
MalwareTrojan.Karagany | Trojan.Karagany can base64 encode and AES-128-CBC encrypt data prior to transmission. |
| T1027.002 Software Packing |
MalwareTrojan.Karagany | Trojan.Karagany samples sometimes use common binary packers such as UPX and Aspack on top of a custom Delphi binary packer. |
| T1033 System Owner/User Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can gather information about the user on a compromised host. |
| T1049 System Network Connections Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can use netstat to collect a list of network connections. |
| T1055.003 Thread Execution Hijacking |
MalwareTrojan.Karagany | Trojan.Karagany can inject a suspended thread of its own process into a new process and initiate via the |
| T1056.001 Keylogging |
MalwareTrojan.Karagany | Trojan.Karagany can capture keystrokes on a compromised host. |
| T1057 Process Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can use Tasklist to collect a list of running tasks. |
| T1059.003 Windows Command Shell |
MalwareTrojan.Karagany | Trojan.Karagany can perform reconnaissance commands on a victim machine via a cmd.exe process. |
| T1070.004 File Deletion |
MalwareTrojan.Karagany | Trojan.Karagany has used plugins with a self-delete capability. |
| T1071.001 Web Protocols |
MalwareTrojan.Karagany | Trojan.Karagany can communicate with C2 via HTTP POST requests. |
| T1074.001 Local Data Staging |
MalwareTrojan.Karagany | Trojan.Karagany can create directories to store plugin output and stage data for exfiltration. |
| T1082 System Information Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can capture information regarding the victim's OS, security, and hardware configuration. |
| T1083 File and Directory Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can enumerate files and directories on a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareTrojan.Karagany | Trojan.Karagany can upload, download, and execute files on the victim. |
| T1113 Screen Capture |
MalwareTrojan.Karagany | Trojan.Karagany can take a desktop screenshot and save the file into |
| T1497.001 System Checks |
MalwareTrojan.Karagany | Trojan.Karagany can detect commonly used and generic virtualization platforms based primarily on drivers and file paths. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTrojan.Karagany | Trojan.Karagany can create a link to itself in the Startup folder to automatically start itself upon system restart. |
| T1555.003 Credentials from Web Browsers |
MalwareTrojan.Karagany | Trojan.Karagany can steal data and credentials from browsers. |
| T1573.002 Asymmetric Cryptography |
MalwareTrojan.Karagany | Trojan.Karagany can secure C2 communications with SSL and TLS. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.