Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareWarzoneRAT | WarzoneRAT can collect data from a compromised host. |
| T1014 Rootkit |
MalwareWarzoneRAT | WarzoneRAT can include a rootkit to hide processes, files, and startup. |
| T1021.001 Remote Desktop Protocol |
MalwareWarzoneRAT | WarzoneRAT has the ability to control an infected PC using RDP. |
| T1021.005 VNC |
MalwareWarzoneRAT | WarzoneRAT has the ability of performing remote desktop access via a VNC console. |
| T1041 Exfiltration Over C2 Channel |
MalwareWarzoneRAT | WarzoneRAT can send collected victim data to its C2 server. |
| T1055 Process Injection |
MalwareWarzoneRAT | WarzoneRAT has the ability to inject malicious DLLs into a specific process for privilege escalation. |
| T1056.001 Keylogging |
MalwareWarzoneRAT | WarzoneRAT has the capability to install a live and offline keylogger, including through the use of the `GetAsyncKeyState` Windows API. |
| T1057 Process Discovery |
MalwareWarzoneRAT | WarzoneRAT can obtain a list of processes on a compromised host. |
| T1059.001 PowerShell |
MalwareWarzoneRAT | WarzoneRAT can use PowerShell to download files and execute commands. |
| T1059.003 Windows Command Shell |
MalwareWarzoneRAT | WarzoneRAT can use `cmd.exe` to execute malicious code. |
| T1082 System Information Discovery |
MalwareWarzoneRAT | WarzoneRAT can collect compromised host information, including OS version, PC name, RAM size, and CPU details. |
| T1083 File and Directory Discovery |
MalwareWarzoneRAT | WarzoneRAT can enumerate directories on a compromise host. |
| T1090 Proxy |
MalwareWarzoneRAT | WarzoneRAT has the capability to act as a reverse proxy. |
| T1095 Non-Application Layer Protocol |
MalwareWarzoneRAT | WarzoneRAT can communicate with its C2 server via TCP over port 5200. |
| T1105 Ingress Tool Transfer |
MalwareWarzoneRAT | WarzoneRAT can download and execute additional files. |
| T1112 Modify Registry |
MalwareWarzoneRAT | WarzoneRAT can create `HKCU\Software\Classes\Folder\shell\open\command` as a new registry key during privilege escalation. |
| T1125 Video Capture |
MalwareWarzoneRAT | WarzoneRAT can access the webcam on a victim's machine. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWarzoneRAT | WarzoneRAT can use XOR 0x45 to decrypt obfuscated code. |
| T1204.002 Malicious File |
MalwareWarzoneRAT | WarzoneRAT has relied on a victim to open a malicious attachment within an email for execution. |
| T1546.015 Component Object Model Hijacking |
MalwareWarzoneRAT | WarzoneRAT can perform COM hijacking by setting the path to itself to the `HKCU\Software\Classes\Folder\shell\open\command` key with a `DelegateExecute` parameter. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareWarzoneRAT | WarzoneRAT can add itself to the `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UIF2IS20VK` Registry keys. |
| T1548.002 Bypass User Account Control |
MalwareWarzoneRAT | WarzoneRAT can use `sdclt.exe` to bypass UAC in Windows 10 to escalate privileges; for older Windows versions WarzoneRAT can use the IFileOperation exploit to bypass the UAC module. |
| T1555.003 Credentials from Web Browsers |
MalwareWarzoneRAT | WarzoneRAT has the capability to grab passwords from numerous web browsers as well as from Outlook and Thunderbird email clients. |
| T1564 Hide Artifacts |
MalwareWarzoneRAT | WarzoneRAT can masquerade the Process Environment Block on a compromised host to hide its attempts to elevate privileges through `IFileOperation`. |
| T1566.001 Spearphishing Attachment |
MalwareWarzoneRAT | WarzoneRAT has been distributed as a malicious attachment within an email. |
| T1573.001 Symmetric Cryptography |
MalwareWarzoneRAT | WarzoneRAT can encrypt its C2 with RC4 with the password `warzone160\x00`. |
| T1685 Disable or Modify Tools |
MalwareWarzoneRAT | WarzoneRAT can disarm Windows Defender during the UAC process to evade detection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.