ATT&CKReferencesTrendMicro Taidoor

TrendMicro Taidoor

Trend Micro. (2012). The Taidoor Campaign. Retrieved November 12, 2014.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareTaidoor

Taidoor can upload data and files from a victim's machine.

T1016
System Network Configuration Discovery
MalwareTaidoor

Taidoor has collected the MAC address of a compromised host; it can also use GetAdaptersInfo to identify network adapters.

T1055.001
Dynamic-link Library Injection
MalwareTaidoor

Taidoor can perform DLL loading.

T1071.001
Web Protocols
MalwareTaidoor

Taidoor has used HTTP GET and POST requests for C2.

T1105
Ingress Tool Transfer
MalwareTaidoor

Taidoor has downloaded additional files onto a compromised host.

T1106
Native API
MalwareTaidoor

Taidoor has the ability to use native APIs for execution including GetProcessHeap, GetProcAddress, and LoadLibrary.

T1204.002
Malicious File
MalwareTaidoor

Taidoor has relied upon a victim to click on a malicious email attachment.

T1547.001
Registry Run Keys / Startup Folder
MalwareTaidoor

Taidoor has modified the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run key for persistence.

T1566.001
Spearphishing Attachment
MalwareTaidoor

Taidoor has been delivered through spearphishing emails.

T1573.001
Symmetric Cryptography
MalwareTaidoor

Taidoor uses RC4 to encrypt the message body of HTTP content.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.