Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareWhisperGate | WhisperGate can Base64 encode strings, store downloaded files in reverse byte order, and use the Eazfuscator tool to obfuscate its third stage. |
| T1055.012 Process Hollowing |
MalwareWhisperGate | WhisperGate has the ability to inject its fourth stage into a suspended process created by the legitimate Windows utility `InstallUtil.exe`. |
| T1106 Native API |
MalwareWhisperGate | WhisperGate has used the `ExitWindowsEx` to flush file buffers to disk and stop running processes and other API calls. |
| T1497.003 Time Based Checks |
MalwareWhisperGate | WhisperGate can pause for 20 seconds to bypass antivirus solutions. |
| T1620 Reflective Code Loading |
MalwareWhisperGate | WhisperGate's downloader can reverse its third stage file bytes and reflectively load the file as a .NET assembly. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.