Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareInvisiMole | InvisiMole can mimic HTTP protocol with custom HTTP “verbs” HIDE, ZVVP, and NOP. |
| T1008 Fallback Channels |
MalwareInvisiMole | InvisiMole has been configured with several servers available for alternate C2 communications. |
| T1010 Application Window Discovery |
MalwareInvisiMole | InvisiMole can enumerate windows and child windows on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareInvisiMole | InvisiMole gathers information on the IP forwarding table, MAC address, configured proxy, and network SSID. |
| T1025 Data from Removable Media |
MalwareInvisiMole | InvisiMole can collect jpeg files from connected MTP devices. |
| T1027 Obfuscated Files or Information |
MalwareInvisiMole | InvisiMole avoids analysis by encrypting all strings, internal files, configuration data and by using a custom executable format. |
| T1027.005 Indicator Removal from Tools |
MalwareInvisiMole | InvisiMole has undergone regular technical improvements in an attempt to evade detection. |
| T1036.004 Masquerade Task or Service |
MalwareInvisiMole | InvisiMole has attempted to disguise itself by registering under a seemingly legitimate service name. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareInvisiMole | InvisiMole has disguised its droppers as legitimate software or documents, matching their original names and locations, and saved its files as mpr.dll in the Windows folder. |
| T1046 Network Service Discovery |
MalwareInvisiMole | InvisiMole can scan the network for open ports and vulnerable instances of RDP and SMB protocols. |
| T1053.005 Scheduled Task |
MalwareInvisiMole | InvisiMole has used scheduled tasks named |
| T1055 Process Injection |
MalwareInvisiMole | InvisiMole can inject itself into another process to avoid detection including use of a technique called ListPlanting that customizes the sorting algorithm in a ListView structure. |
| T1055.002 Portable Executable Injection |
MalwareInvisiMole | InvisiMole can inject its backdoor as a portable executable into a target process. |
| T1055.004 Asynchronous Procedure Call |
MalwareInvisiMole | InvisiMole can inject its code into a trusted process via the APC queue. |
| T1055.015 ListPlanting |
MalwareInvisiMole | InvisiMole has used ListPlanting to inject code into a trusted process. |
| T1056.001 Keylogging |
MalwareInvisiMole | InvisiMole can capture keystrokes on a compromised host. |
| T1057 Process Discovery |
MalwareInvisiMole | InvisiMole can obtain a list of running processes. |
| T1059.003 Windows Command Shell |
MalwareInvisiMole | InvisiMole can launch a remote shell to execute commands. |
| T1059.007 JavaScript |
MalwareInvisiMole | InvisiMole can use a JavaScript file as part of its execution chain. |
| T1068 Exploitation for Privilege Escalation |
MalwareInvisiMole | InvisiMole has exploited CVE-2007-5633 vulnerability in the speedfan.sys driver to obtain kernel mode privileges. |
| T1070.004 File Deletion |
MalwareInvisiMole | InvisiMole has deleted files and directories including XML and files successfully uploaded to C2 servers. |
| T1071.004 DNS |
MalwareInvisiMole | InvisiMole has used a custom implementation of DNS tunneling to embed C2 communications in DNS requests and replies. |
| T1074.001 Local Data Staging |
MalwareInvisiMole | InvisiMole determines a working directory where it stores all the gathered data about the compromised machine. |
| T1080 Taint Shared Content |
MalwareInvisiMole | InvisiMole can replace legitimate software or documents in the compromised network with their trojanized versions, in an attempt to propagate itself within the network. |
| T1082 System Information Discovery |
MalwareInvisiMole | InvisiMole can gather information on the OS version, computer name, DEP policy, and memory size. |
| T1090.002 External Proxy |
MalwareInvisiMole | InvisiMole InvisiMole can identify proxy servers used by the victim and use them for C2 communication. |
| T1095 Non-Application Layer Protocol |
MalwareInvisiMole | InvisiMole has used TCP to download additional modules. |
| T1105 Ingress Tool Transfer |
MalwareInvisiMole | InvisiMole can upload files to the victim's machine for operations. |
| T1106 Native API |
MalwareInvisiMole | InvisiMole can use winapiexec tool for indirect execution of |
| T1112 Modify Registry |
MalwareInvisiMole | InvisiMole has a command to create, set, copy, or delete a specified Registry key or value. |
| T1113 Screen Capture |
MalwareInvisiMole | InvisiMole can capture screenshots of not only the entire screen, but of each separate window open, in case they are overlapping. |
| T1119 Automated Collection |
MalwareInvisiMole | InvisiMole can sort and collect specific documents as well as generate a list of all files on a newly inserted drive and store them in an encrypted file. |
| T1123 Audio Capture |
MalwareInvisiMole | InvisiMole can record sound using input audio devices. |
| T1124 System Time Discovery |
MalwareInvisiMole | InvisiMole gathers the local system time from the victim’s machine. |
| T1125 Video Capture |
MalwareInvisiMole | InvisiMole can remotely activate the victim’s webcam to capture content. |
| T1132.002 Non-Standard Encoding |
MalwareInvisiMole | InvisiMole can use a modified base32 encoding to encode data within the subdomain of C2 requests. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareInvisiMole | InvisiMole can decrypt, unpack and load a DLL from its resources, or from blobs encrypted with Data Protection API, two-key triple DES, and variations of the XOR cipher. |
| T1203 Exploitation for Client Execution |
MalwareInvisiMole | InvisiMole has installed legitimate but vulnerable Total Video Player software and wdigest.dll library drivers on compromised hosts to exploit stack overflow and input validation vulnerabilities for code execution. |
| T1204.002 Malicious File |
MalwareInvisiMole | InvisiMole can deliver trojanized versions of software and documents, relying on user execution. |
| T1210 Exploitation of Remote Services |
MalwareInvisiMole | InvisiMole can spread within a network via the BlueKeep (CVE-2019-0708) and EternalBlue (CVE-2017-0144) vulnerabilities in RDP and SMB respectively. |
| T1218.002 Control Panel |
MalwareInvisiMole | InvisiMole can register itself for execution and persistence via the Control Panel. |
| T1218.011 Rundll32 |
MalwareInvisiMole | InvisiMole has used rundll32.exe for execution. |
| T1480.001 Environmental Keying |
MalwareInvisiMole | InvisiMole can use Data Protection API to encrypt its components on the victim’s computer, to evade detection, and to make sure the payload can only be decrypted and loaded on one specific compromised computer. |
| T1497.001 System Checks |
MalwareInvisiMole | InvisiMole can check for artifacts of VirtualBox, Virtual PC and VMware environment, and terminate itself if they are detected. |
| T1518 Software Discovery |
MalwareInvisiMole | InvisiMole can collect information about installed software used by specific users, software executed on user login, and software executed by each system. |
| T1518.001 Security Software Discovery |
MalwareInvisiMole | InvisiMole can check for the presence of network sniffers, AV, and BitDefender firewall. |
| T1543.003 Windows Service |
MalwareInvisiMole | InvisiMole can register a Windows service named CsPower as part of its execution chain, and a Windows service named clr_optimization_v2.0.51527_X86 to achieve persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareInvisiMole | InvisiMole can place a lnk file in the Startup Folder to achieve persistence. |
| T1547.009 Shortcut Modification |
MalwareInvisiMole | InvisiMole can use a .lnk shortcut for the Control Panel to establish persistence. |
| T1548.002 Bypass User Account Control |
MalwareInvisiMole | InvisiMole can use fileless UAC bypass and create an elevated COM object to escalate privileges. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.