Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareBISCUIT | BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server. |
| T1027.013 Encrypted/Encoded File |
MalwareSeasalt | Seasalt obfuscates configuration data. |
| T1033 System Owner/User Discovery |
MalwareBISCUIT | BISCUIT has a command to gather the username from the system. |
| T1036.004 Masquerade Task or Service |
MalwareSeasalt | Seasalt has masqueraded as a service called "SaSaut" with a display name of "System Authorization Service" in an apparent attempt to masquerade as a legitimate service. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT1 | The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware. |
| T1056.001 Keylogging |
MalwareBISCUIT | BISCUIT can capture keystrokes. |
| T1057 Process Discovery |
MalwareSeasalt | Seasalt has a command to perform a process listing. |
| T1057 Process Discovery |
MalwareBISCUIT | BISCUIT has a command to enumerate running processes and identify their owners. |
| T1059.003 Windows Command Shell |
MalwareBISCUIT | BISCUIT has a command to launch a command shell on the system. |
| T1059.003 Windows Command Shell |
MalwareCALENDAR | CALENDAR has a command to run cmd.exe to execute commands. |
| T1059.003 Windows Command Shell |
MalwareSeasalt | Seasalt uses cmd.exe to create a reverse shell on the infected endpoint. |
| T1070.004 File Deletion |
MalwareSeasalt | Seasalt has a command to delete a specified file. |
| T1071.001 Web Protocols |
MalwareSeasalt | Seasalt uses HTTP for C2 communications. |
| T1071.005 Publish/Subscribe Protocols |
MalwareGLOOXMAIL | GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol for C2. |
| T1102.002 Bidirectional Communication |
MalwareCALENDAR | The CALENDAR malware communicates through the use of events in Google Calendar. |
| T1105 Ingress Tool Transfer |
MalwareBISCUIT | BISCUIT has a command to download a file from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareSeasalt | Seasalt has a command to download additional files. |
| T1113 Screen Capture |
MalwareBISCUIT | BISCUIT has a command to periodically take screenshots of the system. |
| T1543.003 Windows Service |
MalwareSeasalt | Seasalt is capable of installing itself as a service. |
| T1573.002 Asymmetric Cryptography |
MalwareBISCUIT | BISCUIT uses SSL for encrypting C2 communications. |
| T1574.001 DLL |
MalwareWEBC2 | Variants of WEBC2 achieve persistence by using DLL search order hijacking, usually by copying the DLL file to |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.