Office of Information Security, Health Sector Cybersecurity Coordination Center. (2023, November 16). Emotet Malware: The Enduring and Persistent Threat to the Health Sector. Retrieved June 19, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwareEmotet | Emotet has been observed dropping and executing password grabber modules including Mimikatz. |
| T1027.009 Embedded Payloads |
MalwareEmotet | Emotet has dropped an embedded executable at `%Temp%\setup.exe`. Additionally, Emotet may embed entire code into other files. |
| T1053.005 Scheduled Task |
MalwareEmotet | Emotet has maintained persistence through a scheduled task, e.g. though a .dll file in the Registry. |
| T1134.001 Token Impersonation/Theft |
MalwareEmotet | Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.