Mohanta, A. (2020, November 25). Warzone RAT comes with UAC bypass technique. Retrieved April 7, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwareWarzoneRAT | WarzoneRAT has the capability to install a live and offline keylogger, including through the use of the `GetAsyncKeyState` Windows API. |
| T1059.001 PowerShell |
MalwareWarzoneRAT | WarzoneRAT can use PowerShell to download files and execute commands. |
| T1106 Native API |
MalwareWarzoneRAT | WarzoneRAT can use a variety of API calls on a compromised host. |
| T1112 Modify Registry |
MalwareWarzoneRAT | WarzoneRAT can create `HKCU\Software\Classes\Folder\shell\open\command` as a new registry key during privilege escalation. |
| T1125 Video Capture |
MalwareWarzoneRAT | WarzoneRAT can access the webcam on a victim's machine. |
| T1548.002 Bypass User Account Control |
MalwareWarzoneRAT | WarzoneRAT can use `sdclt.exe` to bypass UAC in Windows 10 to escalate privileges; for older Windows versions WarzoneRAT can use the IFileOperation exploit to bypass the UAC module. |
| T1555.003 Credentials from Web Browsers |
MalwareWarzoneRAT | WarzoneRAT has the capability to grab passwords from numerous web browsers as well as from Outlook and Thunderbird email clients. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.