ATT&CKReferencesCofense RevengeRAT Feb 2019

Cofense RevengeRAT Feb 2019

Gannon, M. (2019, February 11). With Upgrades in Delivery and Support Infrastructure, Revenge RAT Malware is a Bigger Threat. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
MalwareRevenge RAT

Revenge RAT schedules tasks to run malicious scripts at different intervals.

T1056.001
Keylogging
MalwareRevenge RAT

Revenge RAT has a plugin for keylogging.

T1059.001
PowerShell
MalwareRevenge RAT

Revenge RAT uses the PowerShell command Reflection.Assembly to load itself into memory to aid in execution.

T1059.003
Windows Command Shell
MalwareRevenge RAT

Revenge RAT uses cmd.exe to execute commands and run scripts on the victim's machine.

T1102.002
Bidirectional Communication
MalwareRevenge RAT

Revenge RAT used blogpost.com as its primary command and control server during a campaign.

T1123
Audio Capture
MalwareRevenge RAT

Revenge RAT has a plugin for microphone interception.

T1125
Video Capture
MalwareRevenge RAT

Revenge RAT has the ability to access the webcam.

T1202
Indirect Command Execution
MalwareRevenge RAT

Revenge RAT uses the Forfiles utility to execute commands on the system.

T1218.005
Mshta
MalwareRevenge RAT

Revenge RAT uses mshta.exe to run malicious scripts on the system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.