Cherepanov, A.. (2017, July 4). Analysis of TeleBots’ cunning backdoor . Retrieved June 11, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
GroupSandworm Team | Sandworm Team has used backdoors that can delete files used in an attack from an infected system. |
| T1082 System Information Discovery |
GroupSandworm Team | Sandworm Team used a backdoor to enumerate information about the infected system's operating system. |
| T1087.003 Email Account |
GroupSandworm Team | Sandworm Team used malware to enumerate email settings, including usernames and passwords, from the M.E.Doc application. |
| T1140 Deobfuscate/Decode Files or Information |
GroupSandworm Team | Sandworm Team's VBS backdoor can decode Base64-encoded data and save it to the %TEMP% folder. The group also decrypted received information using the Triple DES algorithm and decompresses it using GZip. |
| T1218.011 Rundll32 |
GroupSandworm Team | Sandworm Team used a backdoor which could execute a supplied DLL using rundll32.exe. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.