ATT&CKReferencesSecurelist MiniDuke Feb 2013

Securelist MiniDuke Feb 2013

Kaspersky Lab's Global Research & Analysis Team. (2013, February 27). The MiniDuke Mystery: PDF 0-day Government Spy Assembler 0x29A Micro Backdoor. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareMiniDuke

MiniDuke uses Google Search to identify C2 servers if its primary C2 method via Twitter is not working.

T1102.001
Dead Drop Resolver
MalwareMiniDuke

Some MiniDuke components use Twitter to initially obtain the address of a C2 server or as a backup if no hard-coded C2 server responds.

T1105
Ingress Tool Transfer
MalwareMiniDuke

MiniDuke can download additional encrypted backdoors onto the victim via GIF files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.