ClearSky Cyber Security. (2017, December). Charming Kitten. Retrieved December 27, 2017.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareDownPaper | DownPaper searches and reads the value of the Windows Update Registry Run key. |
| T1033 System Owner/User Discovery |
MalwareDownPaper | DownPaper collects the victim username and sends it to the C2 server. |
| T1059.001 PowerShell |
MalwareDownPaper | DownPaper uses PowerShell for execution. |
| T1059.003 Windows Command Shell |
MalwareDownPaper | DownPaper uses the command line. |
| T1071.001 Web Protocols |
MalwareDownPaper | DownPaper communicates to its C2 server over HTTP. |
| T1082 System Information Discovery |
MalwareDownPaper | DownPaper collects the victim host name and serial number, and then sends the information to the C2 server. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareDownPaper | DownPaper uses PowerShell to add a Registry Run key in order to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.