ATT&CKReferencesCISA MAR-10292089-1.v2 TAIDOOR August 2021

CISA MAR-10292089-1.v2 TAIDOOR August 2021

CISA, FBI, DOD. (2021, August). MAR-10292089-1.v2 – Chinese Remote Access Trojan: TAIDOOR. Retrieved August 24, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareTaidoor

Taidoor can query the Registry on compromised hosts using RegQueryValueExA.

T1016
System Network Configuration Discovery
MalwareTaidoor

Taidoor has collected the MAC address of a compromised host; it can also use GetAdaptersInfo to identify network adapters.

T1027.013
Encrypted/Encoded File
MalwareTaidoor

Taidoor can use encrypted string blocks for obfuscation.

T1055.001
Dynamic-link Library Injection
MalwareTaidoor

Taidoor can perform DLL loading.

T1057
Process Discovery
MalwareTaidoor

Taidoor can use GetCurrentProcessId for process discovery.

T1059.003
Windows Command Shell
MalwareTaidoor

Taidoor can copy cmd.exe into the system temp folder.

T1070.004
File Deletion
MalwareTaidoor

Taidoor can use DeleteFileA to remove files from infected hosts.

T1083
File and Directory Discovery
MalwareTaidoor

Taidoor can search for specific files.

T1095
Non-Application Layer Protocol
MalwareTaidoor

Taidoor can use TCP for C2 communications.

T1106
Native API
MalwareTaidoor

Taidoor has the ability to use native APIs for execution including GetProcessHeap, GetProcAddress, and LoadLibrary.

T1112
Modify Registry
MalwareTaidoor

Taidoor has the ability to modify the Registry on compromised hosts using RegDeleteValueA and RegCreateKeyExA.

T1124
System Time Discovery
MalwareTaidoor

Taidoor can use GetLocalTime and GetSystemTime to collect system time.

T1140
Deobfuscate/Decode Files or Information
MalwareTaidoor

Taidoor can use a stream cipher to decrypt stings used by the malware.

T1573.001
Symmetric Cryptography
MalwareTaidoor

Taidoor uses RC4 to encrypt the message body of HTTP content.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.