ATT&CKReferencesESET PLEAD Malware July 2018

ESET PLEAD Malware July 2018

Cherepanov, A.. (2018, July 9). Certificates stolen from Taiwanese tech‑companies misused in Plead malware campaign. Retrieved May 6, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwarePLEAD

PLEAD samples were found to be highly obfuscated with junk code.

T1555
Credentials from Password Stores
MalwarePLEAD

PLEAD has the ability to steal saved passwords from Microsoft Outlook.

T1555.003
Credentials from Web Browsers
MalwarePLEAD

PLEAD can harvest saved credentials from browsers such as Google Chrome, Microsoft Internet Explorer, and Mozilla Firefox.

T1588.004
Digital Certificates
GroupBlackTech

BlackTech has used valid, stolen digital certificates for some of their malware and tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.