Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1008 Fallback Channels |
MiniDuke uses Google Search to identify C2 servers if its primary C2 method via Twitter is not working. |
| T1027 Obfuscated Files or Information |
MiniDuke can use control flow flattening to obscure code. |
| T1071.001 Web Protocols |
MiniDuke uses HTTP and HTTPS for command and control. |
| T1082 System Information Discovery |
MiniDuke can gather the hostname on a compromised machine. |
| T1083 File and Directory Discovery |
MiniDuke can enumerate local drives. |
| T1090.001 Internal Proxy |
MiniDuke can can use a named pipe to forward communications from one compromised machine with internet access to other compromised machines. |
| T1102.001 Dead Drop Resolver |
Some MiniDuke components use Twitter to initially obtain the address of a C2 server or as a backup if no hard-coded C2 server responds. |
| T1105 Ingress Tool Transfer |
MiniDuke can download additional encrypted backdoors onto the victim via GIF files. |
| T1568.002 Domain Generation Algorithms |
MiniDuke can use DGA to generate new Twitter URLs for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.