Desai, D.. (2015, August 14). Chinese cyber espionage APT group leveraging recently leaked Hacking Team exploits to target a Financial Services Firm. Retrieved January 26, 2016.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHTTPBrowser | HTTPBrowser's installer contains a malicious file named navlu.dll to decrypt and run the RAT. navlu.dll is also the name of a legitimate Symantec DLL. |
| T1070.004 File Deletion |
MalwareHTTPBrowser | HTTPBrowser deletes its original installer file once installation is complete. |
| T1083 File and Directory Discovery |
MalwareHTTPBrowser | HTTPBrowser is capable of listing files, folders, and drives on a victim. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHTTPBrowser | HTTPBrowser has established persistence by setting the |
| T1574.001 DLL |
MalwareHTTPBrowser | HTTPBrowser abuses the Windows DLL load order by using a legitimate Symantec anti-virus binary, VPDN_LU.exe, to load a malicious DLL that mimics a legitimate Symantec DLL, navlu.dll. HTTPBrowser has also used DLL side-loading. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.