Malware.View on attack.mitre.org
Dridex is a prolific banking Trojan that first appeared in 2014. By December 2019, the US Treasury estimated Dridex had infected computers in hundreds of banks and financial institutions in over 40 countries, leading to more than $100 million in theft. Dridex was created from the source code of the Bugat banking Trojan (also known as Cridex).
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
Dridex's strings are obfuscated using RC4. |
| T1053.005 Scheduled Task |
Dridex can maintain persistence via the creation of scheduled tasks within system directories such as `windows\system32\`, `windows\syswow64,` `winnt\system32`, and `winnt\syswow64`. |
| T1071.001 Web Protocols |
Dridex has used POST requests and HTTPS for C2 communications. |
| T1082 System Information Discovery |
Dridex has collected the computer name and OS architecture information from the system. |
| T1090 Proxy |
Dridex contains a backconnect module for tunneling network traffic through a victim's computer. Infected computers become part of a P2P botnet that can relay C2 traffic to other infected peers. |
| T1090.003 Multi-hop Proxy |
Dridex can use multiple layers of proxy servers to hide terminal nodes in its infrastructure. |
| T1106 Native API |
Dridex has used the |
| T1185 Browser Session Hijacking |
Dridex can perform browser attacks via web injects to steal information such as credentials, certificates, and cookies. |
| T1204.002 Malicious File |
Dridex has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1218.010 Regsvr32 |
Dridex can use `regsvr32.exe` to initiate malicious code. |
| T1219 Remote Access Tools |
Dridex contains a module for VNC. |
| T1518 Software Discovery |
Dridex has collected a list of installed software on the system. |
| T1573.001 Symmetric Cryptography |
Dridex has encrypted traffic with RC4. |
| T1573.002 Asymmetric Cryptography |
Dridex has encrypted traffic with RSA. |
| T1574.001 DLL |
Dridex can abuse legitimate Windows executables to side-load malicious DLL files. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.