Glyer, C., Kazanciyan, R. (2012, August 22). The “Hikit” Rootkit: Advanced and Persistent Attack Techniques (Part 2). Retrieved November 17, 2024.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
MalwareHikit | |
| T1059.003 Windows Command Shell |
MalwareHikit | Hikit has the ability to create a remote shell and run given commands. |
| T1071.001 Web Protocols |
MalwareHikit | Hikit has used HTTP for C2. |
| T1553.006 Code Signing Policy Modification |
MalwareHikit | Hikit has attempted to disable driver signing verification by tampering with several Registry keys prior to the loading of a rootkit driver component. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.