Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
MalwareMetamorfo | Metamorfo can enumerate all windows on the victim’s machine. |
| T1056.002 GUI Input Capture |
MalwareMetamorfo | Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims. |
| T1059.005 Visual Basic |
MalwareMetamorfo | Metamorfo has used VBS code on victims’ systems. |
| T1070 Indicator Removal |
MalwareMetamorfo | Metamorfo has a command to delete a Registry key it uses, |
| T1082 System Information Discovery |
MalwareMetamorfo | Metamorfo has collected the hostname and operating system version from the compromised host. |
| T1083 File and Directory Discovery |
MalwareMetamorfo | Metamorfo has searched the Program Files directories for specific folders and has searched for strings related to its mutexes. |
| T1095 Non-Application Layer Protocol |
MalwareMetamorfo | Metamorfo has used raw TCP for C2. |
| T1102.003 One-Way Communication |
MalwareMetamorfo | Metamorfo has downloaded a zip file for execution on the system. |
| T1105 Ingress Tool Transfer |
MalwareMetamorfo | Metamorfo has used MSI files to download additional files to execute. |
| T1112 Modify Registry |
MalwareMetamorfo | Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key. |
| T1113 Screen Capture |
MalwareMetamorfo | Metamorfo can collect screenshots of the victim’s machine. |
| T1119 Automated Collection |
MalwareMetamorfo | Metamorfo has automatically collected mouse clicks, continuous screenshots on the machine, and set timers to collect the contents of the clipboard and website browsing. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMetamorfo | Upon execution, Metamorfo has unzipped itself after being downloaded to the system and has performed string decryption. |
| T1204.002 Malicious File |
MalwareMetamorfo | Metamorfo requires the user to double-click the executable to run the malicious HTA file or to download a malicious installer. |
| T1218.005 Mshta |
MalwareMetamorfo | Metamorfo has used mshta.exe to execute a HTA payload. |
| T1518 Software Discovery |
MalwareMetamorfo | Metamorfo has searched the compromised system for banking applications. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMetamorfo | Metamorfo has configured persistence to the Registry key |
| T1566.001 Spearphishing Attachment |
MalwareMetamorfo | Metamorfo has been delivered to victims via emails with malicious HTML attachments. |
| T1571 Non-Standard Port |
MalwareMetamorfo | Metamorfo has communicated with hosts over raw TCP on port 9999. |
| T1574.001 DLL |
MalwareMetamorfo | Metamorfo has side-loaded its malicious DLL file. |
| T1685 Disable or Modify Tools |
MalwareMetamorfo | Metamorfo has a function to kill processes associated with defenses and can prevent certain processes from launching. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.