ATT&CKReferencesRed Canary NETWIRE January 2020

Red Canary NETWIRE January 2020

Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples27

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareNETWIRE

NETWIRE can discover and close windows on controlled systems.

T1016
System Network Configuration Discovery
MalwareNETWIRE

NETWIRE can collect the IP address of a compromised host.

T1027.002
Software Packing
MalwareNETWIRE

NETWIRE has used .NET packer tools to evade detection.

T1027.011
Fileless Storage
MalwareNETWIRE

NETWIRE can store its configuration information in the Registry under `HKCU:\Software\Netwire`.

T1036.005
Match Legitimate Resource Name or Location
MalwareNETWIRE

NETWIRE has masqueraded as legitimate software including TeamViewer and macOS Finder.

T1053.003
Cron
MalwareNETWIRE

NETWIRE can use crontabs to establish persistence.

T1055
Process Injection
MalwareNETWIRE

NETWIRE can inject code into system processes including notepad.exe, svchost.exe, and vbc.exe.

T1055.012
Process Hollowing
MalwareNETWIRE

The NETWIRE payload has been injected into benign Microsoft executables via process hollowing.

T1056.001
Keylogging
MalwareNETWIRE

NETWIRE can perform keylogging.

T1059.003
Windows Command Shell
MalwareNETWIRE

NETWIRE can issue commands using cmd.exe.

T1059.004
Unix Shell
MalwareNETWIRE

NETWIRE has the ability to use /bin/bash and /bin/sh to execute commands.

T1071.001
Web Protocols
MalwareNETWIRE

NETWIRE has the ability to communicate over HTTP.

T1090
Proxy
MalwareNETWIRE

NETWIRE can implement use of proxies to pivot traffic.

T1095
Non-Application Layer Protocol
MalwareNETWIRE

NETWIRE can use TCP in C2 communications.

T1112
Modify Registry
MalwareNETWIRE

NETWIRE can modify the Registry to store its configuration information.

T1113
Screen Capture
MalwareNETWIRE

NETWIRE can capture the victim's screen.

T1119
Automated Collection
MalwareNETWIRE

NETWIRE can automatically archive collected data.

T1543.001
Launch Agent
MalwareNETWIRE

NETWIRE can use launch agents for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareNETWIRE

NETWIRE creates a Registry start-up entry to establish persistence.

T1547.013
XDG Autostart Entries
MalwareNETWIRE

NETWIRE can use XDG Autostart Entries to establish persistence on Linux systems.

T1547.015
Login Items
MalwareNETWIRE

NETWIRE can persist via startup options for Login items.

T1555
Credentials from Password Stores
MalwareNETWIRE

NETWIRE can retrieve passwords from messaging and mail client applications.

T1555.003
Credentials from Web Browsers
MalwareNETWIRE

NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome.

T1560
Archive Collected Data
MalwareNETWIRE

NETWIRE has the ability to compress archived screenshots.

T1564.001
Hidden Files and Directories
MalwareNETWIRE

NETWIRE can copy itself to and launch itself from hidden folders.

T1573
Encrypted Channel
MalwareNETWIRE

NETWIRE can encrypt C2 communications.

T1573.001
Symmetric Cryptography
MalwareNETWIRE

NETWIRE can use AES encryption for C2 data transferred.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.