Llimos, N., Pascual, C.. (2019, February 12). Trickbot Adds Remote Application Credential-Grabbing Capabilities to Its Repertoire. Retrieved March 12, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.004 Credential API Hooking |
MalwareTrickBot | TrickBot has the ability to capture RDP credentials by capturing the |
| T1059.003 Windows Command Shell |
MalwareTrickBot | TrickBot has used macros in Excel documents to download and deploy the malware on the user’s machine. |
| T1204.002 Malicious File |
MalwareTrickBot | TrickBot has attempted to get users to launch malicious documents to deliver its payload. |
| T1552.001 Credentials In Files |
MalwareTrickBot | TrickBot can obtain passwords stored in files from several applications such as Outlook, Filezilla, OpenSSH, OpenVPN and WinSCP. Additionally, it searches for the ".vnc.lnk" affix to steal VNC credentials. |
| T1552.002 Credentials in Registry |
MalwareTrickBot | TrickBot has retrieved PuTTY credentials by querying the |
| T1566.001 Spearphishing Attachment |
MalwareTrickBot | TrickBot has used an email with an Excel sheet containing a malicious macro to deploy the malware |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.