Malware.View on attack.mitre.org
yty is a modular, plugin-based malware framework. The components of the framework are written in a variety of programming languages.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
yty collects files with the following extensions: .ppt, .pptx, .pdf, .doc, .docx, .xls, .xlsx, .docm, .rtf, .inp, .xlsm, .csv, .odt, .pps, .vcf and sends them back to the C2 server. |
| T1016 System Network Configuration Discovery |
yty runs |
| T1018 Remote System Discovery |
yty uses the |
| T1027.002 Software Packing |
yty packs a plugin with UPX. |
| T1027.016 Junk Code Insertion |
yty contains junk code in its binary, likely to confuse malware analysts. |
| T1033 System Owner/User Discovery |
yty collects the victim’s username. |
| T1053.005 Scheduled Task |
yty establishes persistence by creating a scheduled task with the command |
| T1056.001 Keylogging |
yty uses a keylogger plugin to gather keystrokes. |
| T1057 Process Discovery |
yty gets an output of running processes using the |
| T1082 System Information Discovery |
yty gathers the computer name, CPU information, Microsoft Windows version, and runs the command |
| T1083 File and Directory Discovery |
yty gathers information on victim’s drives and has a plugin for document listing. |
| T1102.002 Bidirectional Communication |
yty communicates to the C2 server by retrieving a Google Doc. |
| T1113 Screen Capture |
yty collects screenshots of the victim machine. |
| T1497.001 System Checks |
yty has some basic anti-sandbox detection that tries to detect Virtual PC, Sandboxie, and VMware. |
| T1680 Local Storage Discovery |
yty gathers the the serial number of the main disk volume. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.