Malware.View on attack.mitre.org
Helminth is a backdoor that has at least two variants - one written in VBScript and PowerShell that is delivered via a macros in Excel spreadsheets, and one that is a standalone Windows executable.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
The Helminth config file is encrypted with RC4. |
| T1030 Data Transfer Size Limits |
Helminth splits data into chunks up to 23 bytes and sends the data in DNS queries to its C2 server. |
| T1053.005 Scheduled Task |
Helminth has used a scheduled task for persistence. |
| T1056.001 Keylogging |
The executable version of Helminth has a module to log keystrokes. |
| T1057 Process Discovery |
|
| T1059.001 PowerShell |
One version of Helminth uses a PowerShell script. |
| T1059.003 Windows Command Shell |
Helminth can provide a remote shell. One version of Helminth uses batch scripting. |
| T1059.005 Visual Basic |
One version of Helminth consists of VBScript scripts. |
| T1069.001 Local Groups |
Helminth has checked the local administrators group. |
| T1069.002 Domain Groups |
Helminth has checked for the domain admin group and Exchange Trusted Subsystem groups using the commands |
| T1071.001 Web Protocols |
Helminth can use HTTP for C2. |
| T1071.004 DNS |
Helminth can use DNS for C2. |
| T1074.001 Local Data Staging |
Helminth creates folders to store output from batch scripts prior to sending the information to its C2 server. |
| T1105 Ingress Tool Transfer |
Helminth can download additional files. |
| T1115 Clipboard Data |
The executable version of Helminth has a module to log clipboard contents. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.