Stepanic, D. and Bousseaden, S. (2024, May 15). Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID. Retrieved September 13, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareLatrodectus | Latrodectus can discover the IP and MAC address of a targeted host. |
| T1027.001 Binary Padding |
MalwareLatrodectus | Latrodectus has been obfuscated with a 129 byte sequence of junk data prepended to the file. |
| T1027.002 Software Packing |
MalwareLatrodectus | The Latrodectus payload has been packed for obfuscation. |
| T1027.013 Encrypted/Encoded File |
MalwareLatrodectus | Latrodectus has used a pseudo random number generator (PRNG) algorithm and a rolling XOR key to obfuscate strings. |
| T1033 System Owner/User Discovery |
MalwareLatrodectus | Latrodectus can discover the username of an infected host. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareLatrodectus | Latrodectus has been packed to appear as a component to Bitdefender’s kernel-mode driver, TRUFOS.SYS. |
| T1047 Windows Management Instrumentation |
MalwareLatrodectus | Latrodectus has used WMI in malicious email infection chains to facilitate the installation of remotely-hosted files. |
| T1053.005 Scheduled Task |
MalwareLatrodectus | Latrodectus can create scheduled tasks for persistence. |
| T1057 Process Discovery |
MalwareLatrodectus | Latrodectus can enumerate running processes including process grandchildren on targeted hosts. |
| T1059.003 Windows Command Shell |
MalwareLatrodectus | The Latrodectus command handler can use `cmdexe` to run multiple discovery commands. |
| T1059.007 JavaScript |
MalwareLatrodectus | Latrodectus has used JavaScript files as part its infection chain during malicious spam |
| T1069.002 Domain Groups |
MalwareLatrodectus | Latrodectus can identify domain groups through `cmd.exe /c net group "Domain Admins" /domain`. |
| T1070.004 File Deletion |
MalwareLatrodectus | Latrodectus has the ability to delete itself. |
| T1071.001 Web Protocols |
MalwareLatrodectus | Latrodectus can send registration information to C2 via HTTP `POST`. |
| T1082 System Information Discovery |
MalwareLatrodectus | Latrodectus can gather operating system information. |
| T1083 File and Directory Discovery |
MalwareLatrodectus | Latrodectus can collect desktop filenames. |
| T1087.002 Domain Account |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c net group "Domain Admins" /domain` to identify domain administrator accounts. |
| T1105 Ingress Tool Transfer |
MalwareLatrodectus | Latrodectus can download and execute PEs, DLLs, and shellcode from C2. |
| T1106 Native API |
MalwareLatrodectus | Latrodectus has used multiple Windows API post exploitation including `GetAdaptersInfo`, `CreateToolhelp32Snapshot`, and `CreateProcessW`. |
| T1132.001 Standard Encoding |
MalwareLatrodectus | Latrodectus has Base64-encoded the message body of a HTTP request sent to C2. |
| T1135 Network Share Discovery |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c net view /all` to discover network shares. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLatrodectus | Latrodectus has the ability to deobfuscate encrypted strings. |
| T1218.011 Rundll32 |
MalwareLatrodectus | Latrodectus can use rundll32.exe to execute downloaded DLLs. |
| T1482 Domain Trust Discovery |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c nltest /domain_trusts` to discover domain trusts. |
| T1497.001 System Checks |
MalwareLatrodectus | Latrodectus can determine if it is running in a virtualized environment by checking the OS version, checking the number of running processes, ensuring a 64-bit application is running on a 64-bit host, and checking if the host has a valid MAC address. |
| T1518.001 Security Software Discovery |
MalwareLatrodectus | Latrodectus has the ability to identify installed antivirus products. |
| T1529 System Shutdown/Reboot |
MalwareLatrodectus | Latrodectus has the ability to restart compromised hosts. |
| T1559.001 Component Object Model |
MalwareLatrodectus | Latrodectus can use the Windows Component Object Model (COM) to set scheduled tasks. |
| T1564.004 NTFS File Attributes |
MalwareLatrodectus | Latrodectus can delete itself while its process is still running through the use of an alternate data stream. |
| T1573.001 Symmetric Cryptography |
MalwareLatrodectus | Latrodectus can send RC4 encrypted data over C2 channels. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.