Malware.View on attack.mitre.org
Elise is a custom backdoor Trojan that appears to be used exclusively by Lotus Blossom. It is part of a larger group of tools referred to as LStudio, ST Group, and APT0LSTU.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
Elise executes |
| T1016 System Network Configuration Discovery |
Elise executes |
| T1027.013 Encrypted/Encoded File |
Elise encrypts several of its files, including configuration files. |
| T1036.005 Match Legitimate Resource Name or Location |
If installing itself as a service fails, Elise instead writes itself as a file named svchost.exe saved in %APPDATA%\Microsoft\Network. |
| T1055.001 Dynamic-link Library Injection |
Elise injects DLL files into iexplore.exe. |
| T1057 Process Discovery |
Elise enumerates processes via the |
| T1070.004 File Deletion |
Elise is capable of launching a remote shell on the host to delete itself. |
| T1070.006 Timestomp |
Elise performs timestomping of a CAB file it creates. |
| T1071.001 Web Protocols |
Elise communicates over HTTP or HTTPS for C2. |
| T1074.001 Local Data Staging |
Elise creates a file in |
| T1082 System Information Discovery |
Elise executes |
| T1083 File and Directory Discovery |
A variant of Elise executes |
| T1087.001 Local Account |
Elise executes |
| T1105 Ingress Tool Transfer |
Elise can download additional files from the C2 server for execution. |
| T1132.001 Standard Encoding |
Elise exfiltrates data using cookie values that are Base64-encoded. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.