Rascagneres, P. (2017, May 03). KONNI: A Malware Under The Radar For Years. Retrieved November 5, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareKONNI | KONNI can collect the IP address from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareKONNI | KONNI can collect the username from the victim’s machine. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareKONNI | KONNI has created a shortcut called "Anti virus service.lnk" in an apparent attempt to masquerade as a legitimate file. |
| T1041 Exfiltration Over C2 Channel |
MalwareKONNI | KONNI has sent data and files to its C2 server. |
| T1056.001 Keylogging |
MalwareKONNI | KONNI has the capability to perform keylogging. |
| T1059.001 PowerShell |
MalwareKONNI | KONNI used PowerShell to download and execute a specific 64-bit version of the malware. |
| T1059.003 Windows Command Shell |
MalwareKONNI | KONNI has used cmd.exe to execute arbitrary commands on the infected host across different stages of the infection chain. |
| T1070.004 File Deletion |
MalwareKONNI | KONNI can delete files. |
| T1071.001 Web Protocols |
MalwareKONNI | KONNI has used HTTP POST for C2. |
| T1082 System Information Discovery |
MalwareKONNI | KONNI can gather the OS version, architecture information, hostname, and RAM size information from the victim’s machine and has used |
| T1083 File and Directory Discovery |
MalwareKONNI | A version of KONNI searches for filenames created with a previous version of the malware, suggesting different versions targeted the same victims and the versions may work together. |
| T1105 Ingress Tool Transfer |
MalwareKONNI | KONNI can download files and execute them on the victim’s machine. |
| T1113 Screen Capture |
MalwareKONNI | KONNI can take screenshots of the victim’s machine. |
| T1115 Clipboard Data |
MalwareKONNI | KONNI had a feature to steal data from the clipboard. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareKONNI | A version of KONNI has dropped a Windows shortcut into the Startup folder to establish persistence. |
| T1547.009 Shortcut Modification |
MalwareKONNI | A version of KONNI drops a Windows shortcut on the victim’s machine to establish persistence. |
| T1555.003 Credentials from Web Browsers |
MalwareKONNI | KONNI can steal profiles (containing credential information) from Firefox, Chrome, and Opera. |
| T1680 Local Storage Discovery |
MalwareKONNI | KONNI can gather information on connected drives and disk space from the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.