Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
MalwareMetamorfo | Metamorfo can enumerate all windows on the victim’s machine. |
| T1027.002 Software Packing |
MalwareMetamorfo | Metamorfo has used VMProtect to pack and protect files. |
| T1056.001 Keylogging |
MalwareMetamorfo | Metamorfo has a command to launch a keylogger and capture keystrokes on the victim’s machine. |
| T1070.004 File Deletion |
MalwareMetamorfo | Metamorfo has deleted itself from the system after execution. |
| T1082 System Information Discovery |
MalwareMetamorfo | Metamorfo has collected the hostname and operating system version from the compromised host. |
| T1083 File and Directory Discovery |
MalwareMetamorfo | Metamorfo has searched the Program Files directories for specific folders and has searched for strings related to its mutexes. |
| T1102.003 One-Way Communication |
MalwareMetamorfo | Metamorfo has downloaded a zip file for execution on the system. |
| T1105 Ingress Tool Transfer |
MalwareMetamorfo | Metamorfo has used MSI files to download additional files to execute. |
| T1106 Native API |
MalwareMetamorfo | Metamorfo has used native WINAPI calls. |
| T1112 Modify Registry |
MalwareMetamorfo | Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key. |
| T1115 Clipboard Data |
MalwareMetamorfo | Metamorfo has a function to hijack data from the clipboard by monitoring the contents of the clipboard and replacing the cryptocurrency wallet with the attacker's. |
| T1129 Shared Modules |
MalwareMetamorfo | Metamorfo had used AutoIt to load and execute the DLL payload. |
| T1218.007 Msiexec |
MalwareMetamorfo | Metamorfo has used MsiExec.exe to automatically execute files. |
| T1518.001 Security Software Discovery |
MalwareMetamorfo | Metamorfo collects a list of installed antivirus software from the victim’s system. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMetamorfo | Metamorfo has configured persistence to the Registry key |
| T1565.002 Transmitted Data Manipulation |
MalwareMetamorfo | Metamorfo has a function that can watch the contents of the system clipboard for valid bitcoin addresses, which it then overwrites with the attacker's address. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.