ATT&CKReferencesTrendMicro Trickbot Feb 2019

TrendMicro Trickbot Feb 2019

Llimos, N., Pascual, C.. (2019, February 12). Trickbot Adds Remote Application Credential-Grabbing Capabilities to Its Repertoire. Retrieved March 12, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1056.004
Credential API Hooking
MalwareTrickBot

TrickBot has the ability to capture RDP credentials by capturing the CredEnumerateA API

T1059.003
Windows Command Shell
MalwareTrickBot

TrickBot has used macros in Excel documents to download and deploy the malware on the user’s machine.

T1204.002
Malicious File
MalwareTrickBot

TrickBot has attempted to get users to launch malicious documents to deliver its payload.

T1552.001
Credentials In Files
MalwareTrickBot

TrickBot can obtain passwords stored in files from several applications such as Outlook, Filezilla, OpenSSH, OpenVPN and WinSCP. Additionally, it searches for the ".vnc.lnk" affix to steal VNC credentials.

T1552.002
Credentials in Registry
MalwareTrickBot

TrickBot has retrieved PuTTY credentials by querying the Software\SimonTatham\Putty\Sessions registry key

T1566.001
Spearphishing Attachment
MalwareTrickBot

TrickBot has used an email with an Excel sheet containing a malicious macro to deploy the malware

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.