US-CERT. (2020, February 20). MAR-10271944-1.v1 – North Korean Trojan: HOTCROISSANT. Retrieved May 1, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareHotCroissant | HotCroissant has the ability to identify the IP address of the compromised machine. |
| T1082 System Information Discovery |
MalwareHotCroissant | HotCroissant has the ability to determine if the current user is an administrator, Windows product name, processor name, screen resolution, and physical RAM of the infected host. |
| T1106 Native API |
MalwareHotCroissant | HotCroissant can perform dynamic DLL importing and API lookups using |
| T1573.001 Symmetric Cryptography |
MalwareHotCroissant | HotCroissant has compressed network communications and encrypted them with a custom stream cipher. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.