Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Emotet has been observed dropping and executing password grabber modules including Mimikatz. |
| T1016.002 Wi-Fi Discovery |
Emotet can extract names of all locally reachable Wi-Fi networks and then perform a brute-force attack to spread to new networks. |
| T1021.002 SMB/Windows Admin Shares |
Emotet has leveraged the Admin$, C$, and IPC$ shares for lateral movement. |
| T1027.001 Binary Padding |
Emotet inflates malicious files and malware as an evasion technique. |
| T1027.002 Software Packing |
Emotet has used custom packers to protect its payloads. |
| T1027.009 Embedded Payloads |
Emotet has dropped an embedded executable at `%Temp%\setup.exe`. Additionally, Emotet may embed entire code into other files. |
| T1027.010 Command Obfuscation |
Emotet has obfuscated macros within malicious documents to hide the URLs hosting the malware, CMD.exe arguments, and PowerShell scripts. |
| T1027.013 Encrypted/Encoded File |
Emotet uses obfuscated URLs to download a ZIP file. |
| T1033 System Owner/User Discovery |
Emotet has enumerated all users connected to network shares. |
| T1036.004 Masquerade Task or Service |
Emotet has installed itself as a new service with the service name `Windows Defender System Service` and display name `WinDefService`. |
| T1040 Network Sniffing |
Emotet has been observed to hook network APIs to monitor network traffic. |
| T1041 Exfiltration Over C2 Channel |
Emotet has exfiltrated data over its C2 channel. |
| T1047 Windows Management Instrumentation |
Emotet has used WMI to execute powershell.exe. |
| T1053.005 Scheduled Task |
Emotet has maintained persistence through a scheduled task, e.g. though a .dll file in the Registry. |
| T1055.001 Dynamic-link Library Injection |
Emotet has been observed injecting in to Explorer.exe and other processes. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.