Vachon, F. (2017, October 30). Windigo Still not Windigone: An Ebury Update . Retrieved February 10, 2021.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareEbury | Ebury has implemented a fallback mechanism to begin using a DGA when the attacker hasn't connected to the infected system for three days. |
| T1014 Rootkit |
MalwareEbury | Ebury acts as a user land rootkit using the SSH service. |
| T1059.006 Python |
MalwareEbury | Ebury has used Python to implement its DGA. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareEbury | Ebury has verified C2 domain ownership by decrypting the TXT record using an embedded RSA public key. |
| T1556.003 Pluggable Authentication Modules |
MalwareEbury | Ebury can deactivate PAM modules to tamper with the sshd configuration. |
| T1568.002 Domain Generation Algorithms |
MalwareEbury | Ebury has used a DGA to generate a domain name for C2. |
| T1574.006 Dynamic Linker Hijacking |
MalwareEbury | When Ebury is running as an OpenSSH server, it uses LD_PRELOAD to inject its malicious shared module in to programs launched by SSH sessions. Ebury hooks the following functions from `libc` to inject into subprocesses; `system`, `popen`, `execve`, `execvpe`, `execv`, `execvp`, and `execl`. |
| T1685 Disable or Modify Tools |
MalwareEbury | Ebury can disable SELinux Role-Based Access Control and deactivate PAM modules. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.