FinFisher. (n.d.). Retrieved September 12, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareFinFisher | FinFisher queries Registry values as part of its anti-sandbox checks. |
| T1027 Obfuscated Files or Information |
MalwareFinFisher | FinFisher is heavily obfuscated in many ways, including through the use of spaghetti code in its functions in an effort to confuse disassembly programs. It also uses a custom XOR algorithm to obfuscate code. |
| T1027.002 Software Packing |
MalwareFinFisher | A FinFisher variant uses a custom packer. |
| T1027.016 Junk Code Insertion |
MalwareFinFisher | FinFisher contains junk code in its functions in an effort to confuse disassembly programs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareFinFisher | FinFisher renames one of its .dll files to uxtheme.dll in an apparent attempt to masquerade as a legitimate file. |
| T1055.001 Dynamic-link Library Injection |
MalwareFinFisher | FinFisher injects itself into various processes depending on whether it is low integrity or high integrity. |
| T1056.004 Credential API Hooking |
MalwareFinFisher | FinFisher hooks processes by modifying IAT pointers to CreateWindowEx. |
| T1057 Process Discovery |
MalwareFinFisher | FinFisher checks its parent process for indications that it is running in a sandbox setup. |
| T1082 System Information Discovery |
MalwareFinFisher | FinFisher checks if the victim OS is 32 or 64-bit. |
| T1083 File and Directory Discovery |
MalwareFinFisher | FinFisher enumerates directories and scans for certain files. |
| T1113 Screen Capture |
MalwareFinFisher | FinFisher takes a screenshot of the screen and displays it on top of all other windows for few seconds in an apparent attempt to hide some messages showed by the system during the setup process. |
| T1134.001 Token Impersonation/Theft |
MalwareFinFisher | FinFisher uses token manipulation with NtFilterToken as part of UAC bypass. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFinFisher | FinFisher extracts and decrypts stage 3 malware, which is stored in encrypted resources. |
| T1518.001 Security Software Discovery |
MalwareFinFisher | FinFisher probes the system to check for antimalware processes. |
| T1542.003 Bootkit |
MalwareFinFisher | Some FinFisher variants incorporate an MBR rootkit. |
| T1543.003 Windows Service |
MalwareFinFisher | FinFisher creates a new Windows service with the malicious executable for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFinFisher | FinFisher establishes persistence by creating the Registry key |
| T1548.002 Bypass User Account Control |
MalwareFinFisher | FinFisher performs UAC bypass. |
| T1574.001 DLL |
MalwareFinFisher | FinFisher uses DLL side-loading to load malicious programs. A FinFisher variant also uses DLL search order hijacking. |
| T1685.005 Clear Windows Event Logs |
MalwareFinFisher | FinFisher clears the system event logs using |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.