Unit 42. (2019, February 22). New BabyShark Malware Targets U.S. National Security Think Tanks. Retrieved October 7, 2019.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareBabyShark | BabyShark has executed the |
| T1016 System Network Configuration Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1033 System Owner/User Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1057 Process Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1059.003 Windows Command Shell |
MalwareBabyShark | BabyShark has used cmd.exe to execute commands. |
| T1082 System Information Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1083 File and Directory Discovery |
MalwareBabyShark | BabyShark has used |
| T1132.001 Standard Encoding |
MalwareBabyShark | BabyShark has encoded data using certutil before exfiltration. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBabyShark | BabyShark has added a Registry key to ensure all future macros are enabled for Microsoft Word and Excel as well as for additional persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.