Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1001.002 Steganography |
ZeroT has retrieved stage 2 payloads as Bitmap images that use Least Significant Bit (LSB) steganography. |
| T1016 System Network Configuration Discovery |
ZeroT gathers the victim's IP address and domain information, and then sends it to its C2 server. |
| T1027.002 Software Packing |
Some ZeroT DLL files have been packed with UPX. |
| T1027.013 Encrypted/Encoded File |
ZeroT has encrypted its payload with RC4. |
| T1027.016 Junk Code Insertion |
ZeroT has obfuscated DLLs and functions using dummy API calls inserted between real instructions. |
| T1071.001 Web Protocols |
ZeroT has used HTTP for C2. |
| T1082 System Information Discovery |
ZeroT gathers the victim's computer name, Windows version, and system language, and then sends it to its C2 server. |
| T1105 Ingress Tool Transfer |
ZeroT can download additional payloads onto the victim. |
| T1140 Deobfuscate/Decode Files or Information |
ZeroT shellcode decrypts and decompresses its RC4-encrypted payload. |
| T1543.003 Windows Service |
ZeroT can add a new service to ensure PlugX persists on the system when delivered as another payload onto the system. |
| T1548.002 Bypass User Account Control |
Many ZeroT samples can perform UAC bypass by using eventvwr.exe to execute a malicious file. |
| T1573.001 Symmetric Cryptography |
ZeroT has used RC4 to encrypt C2 traffic. |
| T1574.001 DLL |
ZeroT has used DLL side-loading to load malicious payloads. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.