Karmi, D. (2020, January 4). A Look Into Konni 2019 Campaign. Retrieved April 28, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareKONNI | KONNI has used FTP to exfiltrate reconnaissance data out. |
| T1057 Process Discovery |
MalwareKONNI | KONNI has used the command |
| T1059.003 Windows Command Shell |
MalwareKONNI | KONNI has used cmd.exe to execute arbitrary commands on the infected host across different stages of the infection chain. |
| T1082 System Information Discovery |
MalwareKONNI | KONNI can gather the OS version, architecture information, hostname, and RAM size information from the victim’s machine and has used |
| T1112 Modify Registry |
MalwareKONNI | KONNI has modified registry keys of ComSysApp, Svchost, and xmlProv on the machine to gain persistence. |
| T1132.001 Standard Encoding |
MalwareKONNI | KONNI has used a custom base64 key to encode stolen data before exfiltration. |
| T1134.002 Create Process with Token |
MalwareKONNI | KONNI has duplicated the token of a high integrity process to spawn an instance of cmd.exe under an impersonated user. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKONNI | KONNI has used certutil to download and decode base64 encoded strings and has also devoted a custom section to performing all the components of the deobfuscation process. |
| T1218.011 Rundll32 |
MalwareKONNI | KONNI has used Rundll32 to execute its loader for privilege escalation purposes. |
| T1546.015 Component Object Model Hijacking |
MalwareKONNI | KONNI has modified ComSysApp service to load the malicious DLL payload. |
| T1548.002 Bypass User Account Control |
MalwareKONNI | KONNI has bypassed UAC by performing token impersonation as well as an RPC-based method, this included bypassing UAC set to “AlwaysNotify". |
| T1680 Local Storage Discovery |
MalwareKONNI | KONNI can gather information on connected drives and disk space from the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.