Tartare, M. et al. (2020, May 21). No “Game over” for the Winnti Group. Retrieved August 24, 2020.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwarePipeMon | PipeMon can switch to an alternate C2 domain when a particular date has been reached. |
| T1016 System Network Configuration Discovery |
MalwarePipeMon | PipeMon can collect and send the local IP address, RDP information, and the network adapter physical address as a part of its C2 beacon. |
| T1027.011 Fileless Storage |
MalwarePipeMon | PipeMon has stored its encrypted payload in the Registry under `HKLM\SOFTWARE\Microsoft\Print\Components\`. |
| T1027.013 Encrypted/Encoded File |
MalwarePipeMon | PipeMon modules are stored encrypted on disk. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePipeMon | PipeMon modules are stored on disk with seemingly benign names including use of a file extension associated with a popular word processor. |
| T1055.001 Dynamic-link Library Injection |
MalwarePipeMon | PipeMon can inject its modules into various processes using reflective DLL loading. |
| T1057 Process Discovery |
MalwarePipeMon | PipeMon can iterate over the running processes to find a suitable injection target. |
| T1082 System Information Discovery |
MalwarePipeMon | PipeMon can collect and send OS version and computer name as a part of its C2 beacon. |
| T1095 Non-Application Layer Protocol |
MalwarePipeMon | The PipeMon communication module can use a custom protocol based on TLS over TCP. |
| T1105 Ingress Tool Transfer |
MalwarePipeMon | PipeMon can install additional modules via C2 commands. |
| T1106 Native API |
MalwarePipeMon | PipeMon's first stage has been executed by a call to |
| T1112 Modify Registry |
MalwarePipeMon | PipeMon has modified the Registry to store its encrypted payload. |
| T1124 System Time Discovery |
MalwarePipeMon | PipeMon can send time zone information from a compromised host to C2. |
| T1129 Shared Modules |
MalwarePipeMon | PipeMon has used call to |
| T1134.002 Create Process with Token |
MalwarePipeMon | PipeMon can attempt to gain administrative privileges using token impersonation. |
| T1134.004 Parent PID Spoofing |
MalwarePipeMon | PipeMon can use parent PID spoofing to elevate privileges. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePipeMon | PipeMon can decrypt password-protected executables. |
| T1518.001 Security Software Discovery |
MalwarePipeMon | PipeMon can check for the presence of ESET and Kaspersky security software. |
| T1543.003 Windows Service |
MalwarePipeMon | PipeMon can establish persistence by registering a malicious DLL as an alternative Print Processor which is loaded when the print spooler service starts. |
| T1547.012 Print Processors |
MalwarePipeMon | The PipeMon installer has modified the Registry key |
| T1548.002 Bypass User Account Control |
MalwarePipeMon | PipeMon installer can use UAC bypass techniques to install the payload. |
| T1553.002 Code Signing |
MalwarePipeMon | PipeMon, its installer, and tools are signed with stolen code-signing certificates. |
| T1573.001 Symmetric Cryptography |
MalwarePipeMon | PipeMon communications are RC4 encrypted. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.