Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareGrandoreiro | Grandoreiro has named malicious browser extensions and update files to appear legitimate. |
| T1071.001 Web Protocols |
MalwareGrandoreiro | Grandoreiro has the ability to use HTTP in C2 communications. |
| T1102.002 Bidirectional Communication |
MalwareGrandoreiro | Grandoreiro can utilize web services including Google sites to send and receive C2 data. |
| T1105 Ingress Tool Transfer |
MalwareGrandoreiro | Grandoreiro can download its second stage from a hardcoded URL within the loader's code. |
| T1115 Clipboard Data |
MalwareGrandoreiro | Grandoreiro can capture clipboard data from a compromised host. |
| T1176.001 Browser Extensions |
MalwareGrandoreiro | Grandoreiro can use malicious browser extensions to steal cookies and other user information. |
| T1185 Browser Session Hijacking |
MalwareGrandoreiro | Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1189 Drive-by Compromise |
MalwareGrandoreiro | Grandoreiro has used compromised websites and Google Ads to bait victims into downloading its installer. |
| T1204.001 Malicious Link |
MalwareGrandoreiro | Grandoreiro has used malicious links to gain execution on victim machines. |
| T1204.002 Malicious File |
MalwareGrandoreiro | Grandoreiro has infected victims via malicious attachments. |
| T1539 Steal Web Session Cookie |
MalwareGrandoreiro | Grandoreiro can steal the victim's cookies to use for duplicating the active session from another device. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareGrandoreiro | Grandoreiro can use run keys and create link files in the startup folder for persistence. |
| T1547.009 Shortcut Modification |
MalwareGrandoreiro | Grandoreiro can write or modify browser shortcuts to enable launching of malicious browser extensions. |
| T1555.003 Credentials from Web Browsers |
MalwareGrandoreiro | Grandoreiro can steal cookie data and credentials from Google Chrome. |
| T1566.002 Spearphishing Link |
MalwareGrandoreiro | Grandoreiro has been spread via malicious links embedded in e-mails. |
| T1573.002 Asymmetric Cryptography |
MalwareGrandoreiro | Grandoreiro can use SSL in C2 communication. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.