ATT&CKReferencesUptycs Warzone UAC Bypass November 2020

Uptycs Warzone UAC Bypass November 2020

Mohanta, A. (2020, November 25). Warzone RAT comes with UAC bypass technique. Retrieved April 7, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareWarzoneRAT

WarzoneRAT has the capability to install a live and offline keylogger, including through the use of the `GetAsyncKeyState` Windows API.

T1059.001
PowerShell
MalwareWarzoneRAT

WarzoneRAT can use PowerShell to download files and execute commands.

T1106
Native API
MalwareWarzoneRAT

WarzoneRAT can use a variety of API calls on a compromised host.

T1112
Modify Registry
MalwareWarzoneRAT

WarzoneRAT can create `HKCU\Software\Classes\Folder\shell\open\command` as a new registry key during privilege escalation.

T1125
Video Capture
MalwareWarzoneRAT

WarzoneRAT can access the webcam on a victim's machine.

T1548.002
Bypass User Account Control
MalwareWarzoneRAT

WarzoneRAT can use `sdclt.exe` to bypass UAC in Windows 10 to escalate privileges; for older Windows versions WarzoneRAT can use the IFileOperation exploit to bypass the UAC module.

T1555.003
Credentials from Web Browsers
MalwareWarzoneRAT

WarzoneRAT has the capability to grab passwords from numerous web browsers as well as from Outlook and Thunderbird email clients.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.