ATT&CKReferencesKaspersky Flame Functionality

Kaspersky Flame Functionality

Gostev, A. (2012, May 30). Flame: Bunny, Frog, Munch and BeetleJuice…. Retrieved March 1, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1036.010
Masquerade Account Name
MalwareFlame

Flame can create backdoor accounts with login `HelpAssistant` on domain connected systems if appropriate rights are available.

T1123
Audio Capture
MalwareFlame

Flame can record audio using any existing hardware recording devices.

T1136.001
Local Account
MalwareFlame

Flame can create backdoor accounts with login “HelpAssistant” on domain connected systems if appropriate rights are available.

T1210
Exploitation of Remote Services
MalwareFlame

Flame can use MS10-061 to exploit a print spooler vulnerability in a remote system with a shared printer in order to move laterally.

T1518.001
Security Software Discovery
MalwareFlame

Flame identifies security software such as antivirus through the Security module.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.