GReAT. (2019, May 13). ScarCruft continues to evolve, introduces Bluetooth harvester. Retrieved June 4, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
GroupAPT37 | APT37 obfuscates strings and payloads. |
| T1027.003 Steganography |
GroupAPT37 | APT37 uses steganography to send images to users that are embedded with shellcode. |
| T1082 System Information Discovery |
MalwareROKRAT | ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems. |
| T1083 File and Directory Discovery |
MalwareROKRAT | ROKRAT has the ability to gather a list of files and directories on the infected system. |
| T1102.002 Bidirectional Communication |
MalwareROKRAT | ROKRAT has used legitimate social networking sites and cloud platforms (including but not limited to Twitter, Yandex, Dropbox, and Mediafire) for C2 communications. |
| T1105 Ingress Tool Transfer |
GroupAPT37 | APT37 has downloaded second stage malware from compromised websites. |
| T1113 Screen Capture |
MalwareROKRAT | ROKRAT can capture screenshots of the infected system using the `gdi32` library. |
| T1120 Peripheral Device Discovery |
GroupAPT37 | APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices. |
| T1123 Audio Capture |
MalwareROKRAT | ROKRAT has an audio capture and eavesdropping module. |
| T1548.002 Bypass User Account Control |
GroupAPT37 | APT37 has a function in the initial dropper to bypass Windows UAC in order to execute the next payload with higher privileges. |
| T1566.001 Spearphishing Attachment |
GroupAPT37 | APT37 delivers malware using spearphishing emails with malicious HWP attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.