Gannon, M. (2019, February 11). With Upgrades in Delivery and Support Infrastructure, Revenge RAT Malware is a Bigger Threat. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1053.005 Scheduled Task |
MalwareRevenge RAT | Revenge RAT schedules tasks to run malicious scripts at different intervals. |
| T1056.001 Keylogging |
MalwareRevenge RAT | Revenge RAT has a plugin for keylogging. |
| T1059.001 PowerShell |
MalwareRevenge RAT | Revenge RAT uses the PowerShell command |
| T1059.003 Windows Command Shell |
MalwareRevenge RAT | Revenge RAT uses cmd.exe to execute commands and run scripts on the victim's machine. |
| T1102.002 Bidirectional Communication |
MalwareRevenge RAT | Revenge RAT used blogpost.com as its primary command and control server during a campaign. |
| T1123 Audio Capture |
MalwareRevenge RAT | Revenge RAT has a plugin for microphone interception. |
| T1125 Video Capture |
MalwareRevenge RAT | Revenge RAT has the ability to access the webcam. |
| T1202 Indirect Command Execution |
MalwareRevenge RAT | Revenge RAT uses the Forfiles utility to execute commands on the system. |
| T1218.005 Mshta |
MalwareRevenge RAT | Revenge RAT uses mshta.exe to run malicious scripts on the system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.