Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Hikit can upload files from compromised machines. |
| T1014 Rootkit |
|
| T1059.003 Windows Command Shell |
Hikit has the ability to create a remote shell and run given commands. |
| T1071.001 Web Protocols |
Hikit has used HTTP for C2. |
| T1090.001 Internal Proxy |
Hikit supports peer connections. |
| T1105 Ingress Tool Transfer |
Hikit has the ability to download files to a compromised host. |
| T1553.004 Install Root Certificate |
Hikit installs a self-generated certificate to the local trust store as a root CA and Trusted Publisher. |
| T1553.006 Code Signing Policy Modification |
Hikit has attempted to disable driver signing verification by tampering with several Registry keys prior to the loading of a rootkit driver component. |
| T1566 Phishing |
Hikit has been spread through spear phishing. |
| T1573.001 Symmetric Cryptography |
Hikit performs XOR encryption. |
| T1574.001 DLL |
Hikit has used DLL to load |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.