ATT&CKReferencesTrend Micro Emotet Jan 2019

Trend Micro Emotet Jan 2019

Trend Micro. (2019, January 16). Exploring Emotet's Activities . Retrieved March 25, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareEmotet

Emotet has been observed dropping and executing password grabber modules including Mimikatz.

T1027.002
Software Packing
MalwareEmotet

Emotet has used custom packers to protect its payloads.

T1027.010
Command Obfuscation
MalwareEmotet

Emotet has obfuscated macros within malicious documents to hide the URLs hosting the malware, CMD.exe arguments, and PowerShell scripts.

T1041
Exfiltration Over C2 Channel
MalwareEmotet

Emotet has exfiltrated data over its C2 channel.

T1059.001
PowerShell
MalwareEmotet

Emotet has used Powershell to retrieve the malicious payload and download additional resources like Mimikatz.

T1059.005
Visual Basic
MalwareEmotet

Emotet has sent Microsoft Word documents with embedded macros that will invoke scripts to download additional payloads.

T1555.003
Credentials from Web Browsers
MalwareEmotet

Emotet has been observed dropping browser password grabber modules.

T1566.001
Spearphishing Attachment
MalwareEmotet

Emotet has been delivered by phishing emails containing attachments.

T1573.001
Symmetric Cryptography
MalwareEmotet

Emotet is known to use RSA keys for encrypting C2 traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.