ATT&CKReferencesRed Canary Dridex Threat Report 2021

Red Canary Dridex Threat Report 2021

Red Canary. (2021, February 9). Dridex - Red Canary Threat Detection Report. Retrieved August 3, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
MalwareDridex

Dridex can maintain persistence via the creation of scheduled tasks within system directories such as `windows\system32\`, `windows\syswow64,` `winnt\system32`, and `winnt\syswow64`.

T1218.010
Regsvr32
MalwareDridex

Dridex can use `regsvr32.exe` to initiate malicious code.

T1574.001
DLL
MalwareDridex

Dridex can abuse legitimate Windows executables to side-load malicious DLL files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.