ATT&CKReferencesF-Secure Sofacy 2015

F-Secure Sofacy 2015

F-Secure. (2015, September 8). Sofacy Recycles Carberp and Metasploit Code. Retrieved August 3, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareJHUHUGIT

Many strings in JHUHUGIT are obfuscated with a XOR algorithm.

T1055
Process Injection
MalwareJHUHUGIT

JHUHUGIT performs code injection injecting its own functions to browser processes.

T1218.011
Rundll32
MalwareJHUHUGIT

JHUHUGIT is executed using rundll32.exe.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.