Kasidet

S0088

Malware.View on attack.mitre.org

About this malware

Kasidet is a backdoor that has been dropped by using malicious VBA macros.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1056.001
Keylogging

Kasidet has the ability to initiate keylogging.

T1057
Process Discovery

Kasidet has the ability to search for a given process name in processes currently running in the system.

T1059.003
Windows Command Shell

Kasidet can execute commands using cmd.exe.

T1082
System Information Discovery

Kasidet has the ability to obtain a victim's system name and operating system version.

T1083
File and Directory Discovery

Kasidet has the ability to search for a given filename on a victim.

T1105
Ingress Tool Transfer

Kasidet has the ability to download and execute additional files.

T1113
Screen Capture

Kasidet has the ability to initiate keylogging and screen captures.

T1518.001
Security Software Discovery

Kasidet has the ability to identify any anti-virus installed on the infected system.

T1547.001
Registry Run Keys / Startup Folder

Kasidet creates a Registry Run key to establish persistence.

T1686
Disable or Modify System Firewall

Kasidet has the ability to change firewall settings to allow a plug-in to be downloaded.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Zscaler Kasidet Open source
    Yadav, A., et al. (2016, January 29). Malicious Office files dropping Kasidet and Dridex. Retrieved March 24, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.