Malware.View on attack.mitre.org
Crimson is a remote access Trojan that has been used by Transparent Tribe since at least 2016.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Crimson can collect information from a compromised host. |
| T1012 Query Registry |
Crimson can check the Registry for the presence of |
| T1016 System Network Configuration Discovery |
Crimson contains a command to collect the victim MAC address and LAN IP. |
| T1025 Data from Removable Media |
Crimson contains a module to collect data from removable drives. |
| T1033 System Owner/User Discovery |
Crimson can identify the user on a targeted system. |
| T1041 Exfiltration Over C2 Channel |
Crimson can exfiltrate stolen information over its C2. |
| T1056.001 Keylogging |
Crimson can use a module to perform keylogging on compromised hosts. |
| T1057 Process Discovery |
Crimson contains a command to list processes. |
| T1059.003 Windows Command Shell |
Crimson has the ability to execute commands with the COMSPEC environment variable. |
| T1070.004 File Deletion |
Crimson has the ability to delete files from a compromised host. |
| T1071.001 Web Protocols |
Crimson can use a HTTP GET request to download its final payload. |
| T1082 System Information Discovery |
Crimson contains a command to collect the victim PC name and operating system. |
| T1083 File and Directory Discovery |
Crimson contains commands to list files and directories, as well as search for files matching certain extensions from a defined list. |
| T1091 Replication Through Removable Media |
Crimson can spread across systems by infecting removable media. |
| T1095 Non-Application Layer Protocol |
Crimson uses a custom TCP protocol for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.