Gostev, A. (2012, May 28). The Flame: Questions and Answers. Retrieved March 1, 2017.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.010 Masquerade Account Name |
MalwareFlame | Flame can create backdoor accounts with login `HelpAssistant` on domain connected systems if appropriate rights are available. |
| T1091 Replication Through Removable Media |
MalwareFlame | Flame contains modules to infect USB sticks and spread laterally to other Windows systems the stick is plugged into using Autorun functionality. |
| T1113 Screen Capture |
MalwareFlame | Flame can take regular screenshots when certain applications are open that are sent to the command and control server. |
| T1123 Audio Capture |
MalwareFlame | Flame can record audio using any existing hardware recording devices. |
| T1136.001 Local Account |
MalwareFlame | Flame can create backdoor accounts with login “HelpAssistant” on domain connected systems if appropriate rights are available. |
| T1210 Exploitation of Remote Services |
MalwareFlame | Flame can use MS10-061 to exploit a print spooler vulnerability in a remote system with a shared printer in order to move laterally. |
| T1518.001 Security Software Discovery |
MalwareFlame | Flame identifies security software such as antivirus through the Security module. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.