Malware.View on attack.mitre.org
BadPatch is a Windows Trojan that was used in a Gaza Hackers-linked campaign.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
BadPatch collects files from the local system that have the following extensions, then prepares them for exfiltration: .xls, .xlsx, .pdf, .mdb, .rar, .zip, .doc, .docx. |
| T1056.001 Keylogging |
BadPatch has a keylogging capability. |
| T1071.001 Web Protocols |
BadPatch uses HTTP for C2. |
| T1071.003 Mail Protocols |
BadPatch uses SMTP for C2. |
| T1074.001 Local Data Staging |
BadPatch stores collected data in log files before exfiltration. |
| T1082 System Information Discovery |
BadPatch collects the OS system, OS version, MAC address, and the computer name from the victim’s machine. |
| T1083 File and Directory Discovery |
BadPatch searches for files with specific file extensions. |
| T1105 Ingress Tool Transfer |
BadPatch can download and execute or update malware. |
| T1113 Screen Capture |
BadPatch captures screenshots in .jpg format and then exfiltrates them. |
| T1497.001 System Checks |
BadPatch attempts to detect if it is being run in a Virtual Machine (VM) using a WMI query for disk drive name, BIOS, and motherboard information. |
| T1518.001 Security Software Discovery |
BadPatch uses WMI to enumerate installed security products in the victim’s environment. |
| T1547.001 Registry Run Keys / Startup Folder |
BadPatch establishes a foothold by adding a link to the malware executable in the startup folder. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.