ATT&CKReferencesPicus Emotet Dec 2018

Picus Emotet Dec 2018

Özarslan, S. (2018, December 21). The Christmas Card you never wanted - A new wave of Emotet is back to wreak havoc. Retrieved March 25, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareEmotet

Emotet has obfuscated macros within malicious documents to hide the URLs hosting the malware, CMD.exe arguments, and PowerShell scripts.

T1055.001
Dynamic-link Library Injection
MalwareEmotet

Emotet has been observed injecting in to Explorer.exe and other processes.

T1059.001
PowerShell
MalwareEmotet

Emotet has used Powershell to retrieve the malicious payload and download additional resources like Mimikatz.

T1059.003
Windows Command Shell
MalwareEmotet

Emotet has used cmd.exe to run a PowerShell script.

T1059.005
Visual Basic
MalwareEmotet

Emotet has sent Microsoft Word documents with embedded macros that will invoke scripts to download additional payloads.

T1547.001
Registry Run Keys / Startup Folder
MalwareEmotet

Emotet has been observed adding the downloaded payload to the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run key to maintain persistence.

T1566.001
Spearphishing Attachment
MalwareEmotet

Emotet has been delivered by phishing emails containing attachments.

T1566.002
Spearphishing Link
MalwareEmotet

Emotet has been delivered by phishing emails containing links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.