ATT&CKReferencesSekoiaBourhis_DiceLoader_Feb2024

SekoiaBourhis_DiceLoader_Feb2024

Bourhis, P., Sekoia TDR. (2024, February 1). Unveiling the intricacies of DiceLoader. Retrieved May 14, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareLizar

Lizar has retrieved network information from a compromised host, such as the MAC address.

T1027
Obfuscated Files or Information
MalwareLizar

Lizar has obfuscated the fingerprint of the victim system, the local IP address, and the Fowler-Noll-V 1 (FNV-1) hash of the local IP address using an XOR operation. The data is then sent to the C2 server.

T1033
System Owner/User Discovery
MalwareLizar

Lizar can collect the username from the system.

T1082
System Information Discovery
MalwareLizar

Lizar can collect the computer name from the machine.

T1095
Non-Application Layer Protocol
MalwareLizar

Lizar has used a raw TCP connection to communicate with the C2 server.

T1105
Ingress Tool Transfer
MalwareLizar

Lizar can download additional plugins, files, and tools.

T1132.002
Non-Standard Encoding
MalwareLizar

Lizar has used a complex XOR operation to obfuscate C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwareLizar

Lizar has decrypted its configuration data, such as the C2 IP address, ports and other network communication.

T1620
Reflective Code Loading
MalwareLizar

Lizar has used the Reflective DLL injection module from Github to inject itself into a process’s memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.