Shivtarkar, N. and Kumar, A. (2022, June 9). Lyceum .NET DNS Backdoor. Retrieved June 23, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareDnsSystem | DnsSystem can upload files from infected machines after receiving a command with `uploaddd` in the string. |
| T1033 System Owner/User Discovery |
MalwareDnsSystem | DnsSystem can use the Windows user name to create a unique identification for infected users and systems. |
| T1041 Exfiltration Over C2 Channel |
MalwareDnsSystem | DnsSystem can exfiltrate collected data to its C2 server. |
| T1059.003 Windows Command Shell |
MalwareDnsSystem | DnsSystem can use `cmd.exe` for execution. |
| T1071.004 DNS |
MalwareDnsSystem | DnsSystem can direct queries to custom DNS servers and return C2 commands using TXT records. |
| T1105 Ingress Tool Transfer |
MalwareDnsSystem | DnsSystem can download files to compromised systems after receiving a command with the string `downloaddd`. |
| T1132.001 Standard Encoding |
MalwareDnsSystem | DnsSystem can Base64 encode data sent to C2. |
| T1204.002 Malicious File |
MalwareDnsSystem | DnsSystem has lured victims into opening macro-enabled Word documents for execution. |
| T1204.002 Malicious File |
GroupHEXANE | HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDnsSystem | DnsSystem can write itself to the Startup folder to gain persistence. |
| T1583.002 DNS Server |
GroupHEXANE | HEXANE has set up custom DNS servers to send commands to compromised hosts via TXT records. |
| T1588.002 Tool |
GroupHEXANE | HEXANE has acquired, and sometimes customized, open source tools such as Mimikatz, Empire, VNC remote access software, and DIG.net. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.