Malware.View on attack.mitre.org
Duqu is a malware platform that uses a modular approach to extend functionality after deployment within a target network.
| Technique | Procedure example |
|---|---|
| T1001.002 Steganography |
When the Duqu command and control is operating over HTTP or HTTPS, Duqu uploads data to its controller by appending it to a blank JPG file. |
| T1010 Application Window Discovery |
The discovery modules used with Duqu can collect information on open windows. |
| T1016 System Network Configuration Discovery |
The reconnaissance modules used with Duqu can collect information on network configuration. |
| T1021.002 SMB/Windows Admin Shares |
Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware. |
| T1049 System Network Connections Discovery |
The discovery modules used with Duqu can collect information on network connections. |
| T1053.005 Scheduled Task |
Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware. |
| T1055.001 Dynamic-link Library Injection |
Duqu will inject itself into different processes to evade detection. The selection of the target process is influenced by the security software that is installed on the system (Duqu will inject into different processes depending on which security suite is installed on the infected host). |
| T1055.012 Process Hollowing |
Duqu is capable of loading executable code via process hollowing. |
| T1056.001 Keylogging |
Duqu can track key presses with a keylogger module. |
| T1057 Process Discovery |
The discovery modules used with Duqu can collect information on process details. |
| T1071 Application Layer Protocol |
Duqu uses a custom command and control protocol that communicates over commonly used ports, and is frequently encapsulated by application layer protocols. |
| T1074.001 Local Data Staging |
Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it. |
| T1078 Valid Accounts |
Adversaries can instruct Duqu to spread laterally by copying itself to shares it has enumerated and for which it has obtained legitimate credentials (via keylogging or other means). The remote host is then infected by using the compromised credentials to schedule a task on remote machines that executes the malware. |
| T1087.001 Local Account |
The discovery modules used with Duqu can collect information on accounts and permissions. |
| T1090.001 Internal Proxy |
Duqu can be configured to have commands relayed over a peer-to-peer network of infected hosts if some of the hosts do not have Internet access. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.