ATT&CKReferencesFortinet Metamorfo Feb 2020

Fortinet Metamorfo Feb 2020

Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareMetamorfo

Metamorfo can enumerate all windows on the victim’s machine.

T1027.002
Software Packing
MalwareMetamorfo

Metamorfo has used VMProtect to pack and protect files.

T1056.001
Keylogging
MalwareMetamorfo

Metamorfo has a command to launch a keylogger and capture keystrokes on the victim’s machine.

T1070.004
File Deletion
MalwareMetamorfo

Metamorfo has deleted itself from the system after execution.

T1082
System Information Discovery
MalwareMetamorfo

Metamorfo has collected the hostname and operating system version from the compromised host.

T1083
File and Directory Discovery
MalwareMetamorfo

Metamorfo has searched the Program Files directories for specific folders and has searched for strings related to its mutexes.

T1102.003
One-Way Communication
MalwareMetamorfo

Metamorfo has downloaded a zip file for execution on the system.

T1105
Ingress Tool Transfer
MalwareMetamorfo

Metamorfo has used MSI files to download additional files to execute.

T1106
Native API
MalwareMetamorfo

Metamorfo has used native WINAPI calls.

T1112
Modify Registry
MalwareMetamorfo

Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key.

T1115
Clipboard Data
MalwareMetamorfo

Metamorfo has a function to hijack data from the clipboard by monitoring the contents of the clipboard and replacing the cryptocurrency wallet with the attacker's.

T1129
Shared Modules
MalwareMetamorfo

Metamorfo had used AutoIt to load and execute the DLL payload.

T1218.007
Msiexec
MalwareMetamorfo

Metamorfo has used MsiExec.exe to automatically execute files.

T1518.001
Security Software Discovery
MalwareMetamorfo

Metamorfo collects a list of installed antivirus software from the victim’s system.

T1547.001
Registry Run Keys / Startup Folder
MalwareMetamorfo

Metamorfo has configured persistence to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run, Spotify =% APPDATA%\Spotify\Spotify.exe and used .LNK files in the startup folder to achieve persistence.

T1565.002
Transmitted Data Manipulation
MalwareMetamorfo

Metamorfo has a function that can watch the contents of the system clipboard for valid bitcoin addresses, which it then overwrites with the attacker's address.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.