Kaspersky Lab's Global Research & Analysis Team. (2017, August 30). Introducing WhiteBear. Retrieved September 21, 2017.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareGazer | Gazer logs its actions into files that are encrypted with 3DES. It also uses RSA to encrypt resources. |
| T1033 System Owner/User Discovery |
MalwareGazer | Gazer obtains the current user's security identifier. |
| T1053.005 Scheduled Task |
MalwareGazer | Gazer can establish persistence by creating a scheduled task. |
| T1055 Process Injection |
MalwareGazer | Gazer injects its communication module into an Internet accessible process through which it performs C2. |
| T1055.003 Thread Execution Hijacking |
MalwareGazer | Gazer performs thread execution hijacking to inject its orchestrator into a running thread from a remote process. |
| T1070.004 File Deletion |
MalwareGazer | Gazer has commands to delete files and persistence mechanisms from the victim. |
| T1105 Ingress Tool Transfer |
MalwareGazer | Gazer can execute a task to download a file. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGazer | Gazer can establish persistence by creating a .lnk file in the Start menu. |
| T1547.009 Shortcut Modification |
MalwareGazer | Gazer can establish persistence by creating a .lnk file in the Start menu or by modifying existing .lnk files to execute the malware through cmd.exe. |
| T1553.002 Code Signing |
MalwareGazer | Gazer versions are signed with various valid certificates; one was likely faked and issued by Comodo for "Solid Loop Ltd," and another was issued for "Ultimate Computer Support Ltd." |
| T1573.001 Symmetric Cryptography |
MalwareGazer | Gazer uses custom encryption for C2 that uses 3DES. |
| T1573.002 Asymmetric Cryptography |
MalwareGazer | Gazer uses custom encryption for C2 that uses RSA. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.