ATT&CKReferencesFireEye HIKIT Rootkit Part 2

FireEye HIKIT Rootkit Part 2

Glyer, C., Kazanciyan, R. (2012, August 22). The “Hikit” Rootkit: Advanced and Persistent Attack Techniques (Part 2). Retrieved November 17, 2024.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareHikit

Hikit is a Rootkit that has been used by Axiom.

T1059.003
Windows Command Shell
MalwareHikit

Hikit has the ability to create a remote shell and run given commands.

T1071.001
Web Protocols
MalwareHikit

Hikit has used HTTP for C2.

T1553.006
Code Signing Policy Modification
MalwareHikit

Hikit has attempted to disable driver signing verification by tampering with several Registry keys prior to the loading of a rootkit driver component.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.