Tudorica, R., Maximciuc, A., Vatamanu, C. (2020, March 18). New TrickBot Module Bruteforces RDP Connections, Targets Select Telecommunication Services in US and Hong Kong. Retrieved March 15, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareTrickBot | TrickBot uses module networkDll for process list discovery. |
| T1110.004 Credential Stuffing |
MalwareTrickBot | TrickBot uses brute-force attack against RDP with rdpscanDll module. |
| T1135 Network Share Discovery |
MalwareTrickBot | TrickBot module shareDll/mshareDll discovers network shares via the WNetOpenEnumA API. |
| T1219 Remote Access Tools |
MalwareTrickBot | TrickBot uses vncDll module to remote control the victim machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.