ATT&CKReferencesemotet_hc3_nov2023

emotet_hc3_nov2023

Office of Information Security, Health Sector Cybersecurity Coordination Center. (2023, November 16). Emotet Malware: The Enduring and Persistent Threat to the Health Sector. Retrieved June 19, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareEmotet

Emotet has been observed dropping and executing password grabber modules including Mimikatz.

T1027.009
Embedded Payloads
MalwareEmotet

Emotet has dropped an embedded executable at `%Temp%\setup.exe`. Additionally, Emotet may embed entire code into other files.

T1053.005
Scheduled Task
MalwareEmotet

Emotet has maintained persistence through a scheduled task, e.g. though a .dll file in the Registry.

T1134.001
Token Impersonation/Theft
MalwareEmotet

Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.