Pantazopoulos, N., Henry T. (2018, May 18). Emissary Panda – A potential new malicious tool. Retrieved June 25, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
GroupThreat Group-3390 | A Threat Group-3390 tool can read and decrypt stored Registry values. |
| T1018 Remote System Discovery |
GroupThreat Group-3390 | Threat Group-3390 has used the |
| T1027.013 Encrypted/Encoded File |
GroupThreat Group-3390 | A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder. |
| T1027.015 Compression |
GroupThreat Group-3390 | Threat Group-3390 malware is compressed with LZNT1 compression. |
| T1047 Windows Management Instrumentation |
GroupThreat Group-3390 | A Threat Group-3390 tool can use WMI to execute a binary. |
| T1055.012 Process Hollowing |
GroupThreat Group-3390 | A Threat Group-3390 tool can spawn `svchost.exe` and inject the payload into that process. |
| T1112 Modify Registry |
GroupThreat Group-3390 | A Threat Group-3390 tool has created new Registry keys under `HKEY_CURRENT_USER\Software\Classes\` and `HKLM\SYSTEM\CurrentControlSet\services`. |
| T1543.003 Windows Service |
GroupThreat Group-3390 | Threat Group-3390's malware can create a new service, sometimes naming it after the config information, to gain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupThreat Group-3390 | Threat Group-3390's malware can add a Registry key to `Software\Microsoft\Windows\CurrentVersion\Run` for persistence. |
| T1548.002 Bypass User Account Control |
GroupThreat Group-3390 | A Threat Group-3390 tool can use a public UAC bypass method to elevate privileges. |
| T1574.001 DLL |
GroupThreat Group-3390 | Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.