Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Mosquito uses the |
| T1027.011 Fileless Storage |
Mosquito stores configuration values under the Registry key |
| T1027.013 Encrypted/Encoded File |
Mosquito’s installer is obfuscated with a custom crypter to obfuscate the installer. |
| T1033 System Owner/User Discovery |
Mosquito runs |
| T1047 Windows Management Instrumentation |
Mosquito's installer uses WMI to search for antivirus display names. |
| T1057 Process Discovery |
Mosquito runs |
| T1059.001 PowerShell |
Mosquito can launch PowerShell Scripts. |
| T1059.003 Windows Command Shell |
Mosquito executes cmd.exe and uses a pipe to read the results and send back the output to the C2 server. |
| T1070.004 File Deletion |
Mosquito deletes files using DeleteFileW API call. |
| T1105 Ingress Tool Transfer |
Mosquito can upload and download files to the victim. |
| T1106 Native API |
Mosquito leverages the CreateProcess() and LoadLibrary() calls to execute files with the .dll and .exe extensions. |
| T1112 Modify Registry |
Mosquito can modify Registry keys under |
| T1218.011 Rundll32 |
Mosquito's launcher uses rundll32.exe in a Registry Key value to start the main backdoor capability. |
| T1518.001 Security Software Discovery |
Mosquito's installer searches the Registry and system to see if specific antivirus tools are installed on the system. |
| T1546.015 Component Object Model Hijacking |
Mosquito uses COM hijacking as a method of persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.