Binary Defense. (n.d.). Emotet Evolves With new Wi-Fi Spreader. Retrieved September 8, 2023.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016.002 Wi-Fi Discovery |
MalwareEmotet | Emotet can extract names of all locally reachable Wi-Fi networks and then perform a brute-force attack to spread to new networks. |
| T1021.002 SMB/Windows Admin Shares |
MalwareEmotet | Emotet has leveraged the Admin$, C$, and IPC$ shares for lateral movement. |
| T1027.009 Embedded Payloads |
MalwareEmotet | Emotet has dropped an embedded executable at `%Temp%\setup.exe`. Additionally, Emotet may embed entire code into other files. |
| T1036.004 Masquerade Task or Service |
MalwareEmotet | Emotet has installed itself as a new service with the service name `Windows Defender System Service` and display name `WinDefService`. |
| T1041 Exfiltration Over C2 Channel |
MalwareEmotet | Emotet has exfiltrated data over its C2 channel. |
| T1071.001 Web Protocols |
MalwareEmotet | Emotet has used HTTP for command and control. |
| T1087.003 Email Account |
MalwareEmotet | Emotet has been observed leveraging a module that can scrape email addresses from Outlook. |
| T1106 Native API |
MalwareEmotet | Emotet has used `CreateProcess` to create a new process to run its executable and `WNetEnumResourceW` to enumerate non-hidden shares. |
| T1110.001 Password Guessing |
MalwareEmotet | Emotet has been observed using a hard coded list of passwords to brute force user accounts. |
| T1114 Email Collection |
MalwareEmotet | Emotet has been observed leveraging a module that can scrape email addresses from Outlook. |
| T1132.001 Standard Encoding |
MalwareEmotet | Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Additionally, Emotet has used Base64 to encode data before sending to the C2 server. |
| T1134.001 Token Impersonation/Theft |
MalwareEmotet | Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed. |
| T1135 Network Share Discovery |
MalwareEmotet | Emotet has enumerated non-hidden network shares using `WNetEnumResourceW`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEmotet | Emotet has used a self-extracting RAR file to deliver modules to victims. Emotet has also extracted embedded executables from files using hard-coded buffer offsets. |
| T1543.003 Windows Service |
MalwareEmotet | Emotet has been observed creating new services to maintain persistence. |
| T1570 Lateral Tool Transfer |
MalwareEmotet | Emotet has copied itself to remote systems using the `service.exe` filename. |
| T1571 Non-Standard Port |
MalwareEmotet | Emotet has used HTTP over ports such as 20, 22, 443, 7080, and 50000, in addition to using ports commonly associated with HTTP/S. |
| T1620 Reflective Code Loading |
MalwareEmotet | Emotet has reflectively loaded payloads into memory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.