Malware.View on attack.mitre.org
TYPEFRAME is a remote access tool that has been used by Lazarus Group.
| Technique | Procedure example |
|---|---|
| T1027.011 Fileless Storage |
TYPEFRAME can install and store encrypted configuration data under the Registry key |
| T1027.013 Encrypted/Encoded File |
APIs and strings in some TYPEFRAME variants are RC4 encrypted. Another variant is encoded with XOR. |
| T1059.003 Windows Command Shell |
TYPEFRAME can uninstall malware components using a batch script. TYPEFRAME can execute commands using a shell. |
| T1059.005 Visual Basic |
TYPEFRAME has used a malicious Word document for delivery with VBA macros for execution. |
| T1070.004 File Deletion |
TYPEFRAME can delete files off the system. |
| T1083 File and Directory Discovery |
TYPEFRAME can search directories for files on the victim’s machine. |
| T1090 Proxy |
A TYPEFRAME variant can force the compromised system to function as a proxy server. |
| T1105 Ingress Tool Transfer |
TYPEFRAME can upload and download files to the victim’s machine. |
| T1112 Modify Registry |
TYPEFRAME can install encrypted configuration data under the Registry key |
| T1140 Deobfuscate/Decode Files or Information |
One TYPEFRAME variant decrypts an archive using an RC4 key, then decompresses and installs the decrypted malicious DLL module. Another variant decodes the embedded file by XORing it with the value "0x35". |
| T1204.002 Malicious File |
A Word document delivering TYPEFRAME prompts the user to enable macro execution. |
| T1543.003 Windows Service |
TYPEFRAME variants can add malicious DLL modules as new services.TYPEFRAME can also delete services from the victim’s machine. |
| T1571 Non-Standard Port |
TYPEFRAME has used ports 443, 8080, and 8443 with a FakeTLS method. |
| T1680 Local Storage Discovery |
TYPEFRAME can gather the disk volume information. |
| T1686.003 Windows Host Firewall |
TYPEFRAME can open the Windows Firewall on the victim’s machine to allow incoming connections. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.