Malware.View on attack.mitre.org
ISMInjector is a Trojan used to install another OilRig backdoor, ISMAgent.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
ISMInjector is obfuscated with the off-the-shelf SmartAssembly .NET obfuscator created by red-gate.com. |
| T1053.005 Scheduled Task |
ISMInjector creates scheduled tasks to establish persistence. |
| T1055.012 Process Hollowing |
ISMInjector hollows out a newly created process RegASM.exe and injects its payload into the hollowed process. |
| T1140 Deobfuscate/Decode Files or Information |
ISMInjector uses the |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.