Malware.View on attack.mitre.org
Pteranodon is a custom backdoor used by Gamaredon Group.
| Technique | Procedure example |
|---|---|
| T1027.007 Dynamic API Resolution |
Pteranodon can use a dynamic Windows hashing algorithm to map API components. |
| T1041 Exfiltration Over C2 Channel |
Pteranodon exfiltrates screenshot files to its C2 server. |
| T1053.005 Scheduled Task |
Pteranodon schedules tasks to invoke its components in order to establish persistence. |
| T1059.003 Windows Command Shell |
Pteranodon can use `cmd.exe` for execution on victim systems. |
| T1059.005 Visual Basic |
Pteranodon can use a malicious VBS file for execution. |
| T1070.004 File Deletion |
Pteranodon can delete files that may interfere with it executing. It also can delete temporary files and itself after the initial script executes. |
| T1071.001 Web Protocols |
Pteranodon can use HTTP for C2. |
| T1074.001 Local Data Staging |
Pteranodon creates various subdirectories under |
| T1083 File and Directory Discovery |
Pteranodon identifies files matching certain file extension and copies them to subdirectories it created. |
| T1105 Ingress Tool Transfer |
Pteranodon can download and execute additional files. |
| T1106 Native API |
Pteranodon has used various API calls. |
| T1113 Screen Capture |
Pteranodon can capture screenshots at a configurable interval. |
| T1140 Deobfuscate/Decode Files or Information |
Pteranodon can decrypt encrypted data strings prior to using them. |
| T1218.005 Mshta |
Pteranodon can use mshta.exe to execute an HTA file hosted on a remote server. |
| T1218.011 Rundll32 |
Pteranodon executes functions using rundll32.exe. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.