ATT&CKReferencesBinary Defense Emotes Wi-Fi Spreader

Binary Defense Emotes Wi-Fi Spreader

Binary Defense. (n.d.). Emotet Evolves With new Wi-Fi Spreader. Retrieved September 8, 2023.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1016.002
Wi-Fi Discovery
MalwareEmotet

Emotet can extract names of all locally reachable Wi-Fi networks and then perform a brute-force attack to spread to new networks.

T1021.002
SMB/Windows Admin Shares
MalwareEmotet

Emotet has leveraged the Admin$, C$, and IPC$ shares for lateral movement.

T1027.009
Embedded Payloads
MalwareEmotet

Emotet has dropped an embedded executable at `%Temp%\setup.exe`. Additionally, Emotet may embed entire code into other files.

T1036.004
Masquerade Task or Service
MalwareEmotet

Emotet has installed itself as a new service with the service name `Windows Defender System Service` and display name `WinDefService`.

T1041
Exfiltration Over C2 Channel
MalwareEmotet

Emotet has exfiltrated data over its C2 channel.

T1071.001
Web Protocols
MalwareEmotet

Emotet has used HTTP for command and control.

T1087.003
Email Account
MalwareEmotet

Emotet has been observed leveraging a module that can scrape email addresses from Outlook.

T1106
Native API
MalwareEmotet

Emotet has used `CreateProcess` to create a new process to run its executable and `WNetEnumResourceW` to enumerate non-hidden shares.

T1110.001
Password Guessing
MalwareEmotet

Emotet has been observed using a hard coded list of passwords to brute force user accounts.

T1114
Email Collection
MalwareEmotet

Emotet has been observed leveraging a module that can scrape email addresses from Outlook.

T1132.001
Standard Encoding
MalwareEmotet

Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Additionally, Emotet has used Base64 to encode data before sending to the C2 server.

T1134.001
Token Impersonation/Theft
MalwareEmotet

Emotet has the ability to duplicate the user’s token. For example, Emotet may use a variant of Google’s ProtoBuf to send messages that specify how code will be executed.

T1135
Network Share Discovery
MalwareEmotet

Emotet has enumerated non-hidden network shares using `WNetEnumResourceW`.

T1140
Deobfuscate/Decode Files or Information
MalwareEmotet

Emotet has used a self-extracting RAR file to deliver modules to victims. Emotet has also extracted embedded executables from files using hard-coded buffer offsets.

T1543.003
Windows Service
MalwareEmotet

Emotet has been observed creating new services to maintain persistence.

T1570
Lateral Tool Transfer
MalwareEmotet

Emotet has copied itself to remote systems using the `service.exe` filename.

T1571
Non-Standard Port
MalwareEmotet

Emotet has used HTTP over ports such as 20, 22, 443, 7080, and 50000, in addition to using ports commonly associated with HTTP/S.

T1620
Reflective Code Loading
MalwareEmotet

Emotet has reflectively loaded payloads into memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.