The BlackBerry Research & Intelligence Team. (2020, October). BAHAMUT: Hack-for-Hire Masters of Phishing, Fake News, and Fake Apps. Retrieved February 8, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
GroupWindshift | Windshift has used string encoding with floating point calculations. |
| T1033 System Owner/User Discovery |
GroupWindshift | Windshift has used malware to identify the username on a compromised host. |
| T1036 Masquerading |
GroupWindshift | Windshift has used icons mimicking MS Office files to mask malicious executables. Windshift has also attempted to hide executables by changing the file extension to ".scr" to mimic Windows screensavers. |
| T1047 Windows Management Instrumentation |
GroupWindshift | Windshift has used WMI to collect information about target machines. |
| T1057 Process Discovery |
GroupWindshift | Windshift has used malware to enumerate active processes. |
| T1059.005 Visual Basic |
GroupWindshift | Windshift has used Visual Basic 6 (VB6) payloads. |
| T1071.001 Web Protocols |
GroupWindshift | Windshift has used tools that communicate with C2 over HTTP. |
| T1082 System Information Discovery |
GroupWindshift | Windshift has used malware to identify the computer name of a compromised host. |
| T1105 Ingress Tool Transfer |
GroupWindshift | Windshift has used tools to deploy additional payloads to compromised hosts. |
| T1518 Software Discovery |
GroupWindshift | Windshift has used malware to identify installed software. |
| T1518.001 Security Software Discovery |
GroupWindshift | Windshift has used malware to identify installed AV and commonly used forensic and malware analysis tools. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupWindshift | Windshift has created LNK files in the Startup folder to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.