HALFBAKED

S0151

Malware.View on attack.mitre.org

About this malware

HALFBAKED is a malware family consisting of multiple components intended to establish persistence in victim networks.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1047
Windows Management Instrumentation

HALFBAKED can use WMI queries to gather system information.

T1057
Process Discovery

HALFBAKED can obtain information about running processes on the victim.

T1059.001
PowerShell

HALFBAKED can execute PowerShell scripts.

T1070.004
File Deletion

HALFBAKED can delete a specified file.

T1082
System Information Discovery

HALFBAKED can obtain information about the OS, processor, and BIOS.

T1113
Screen Capture

HALFBAKED can obtain screenshots from the victim.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye FIN7 April 2017 Open source
    Carr, N., et al. (2017, April 24). FIN7 Evolution and the Phishing LNK. Retrieved April 24, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.