Malware.View on attack.mitre.org
Reaver is a malware family that has been in the wild since at least late 2016. Reporting indicates victims have primarily been associated with the "Five Poisons," which are movements the Chinese government considers dangerous. The type of malware is rare due to its final payload being in the form of Control Panel items.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
Reaver queries the Registry to determine the correct Startup path to use for persistence. |
| T1016 System Network Configuration Discovery |
Reaver collects the victim's IP address. |
| T1027.013 Encrypted/Encoded File |
Reaver encrypts some of its files with XOR. |
| T1033 System Owner/User Discovery |
Reaver collects the victim's username. |
| T1070.004 File Deletion |
Reaver deletes the original dropped file from the victim. |
| T1071.001 Web Protocols |
Some Reaver variants use HTTP for C2. |
| T1082 System Information Discovery |
Reaver collects system information from the victim, including CPU speed, computer name, ANSI code page, OEM code page identifier for the OS, Microsoft Windows version, and memory information. |
| T1095 Non-Application Layer Protocol |
Some Reaver variants use raw TCP for C2. |
| T1218.002 Control Panel |
Reaver drops and executes a malicious CPL file as its payload. |
| T1543.003 Windows Service |
Reaver installs itself as a new service. |
| T1547.001 Registry Run Keys / Startup Folder |
Reaver creates a shortcut file and saves it in a Startup folder to establish persistence. |
| T1547.009 Shortcut Modification |
Reaver creates a shortcut file and saves it in a Startup folder to establish persistence. |
| T1560.003 Archive via Custom Method |
Reaver encrypts collected data with an incremental XOR key prior to exfiltration. |
| T1680 Local Storage Discovery |
Reaver collects volume serial number from the victim. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.