Malware.View on attack.mitre.org
KeyBoy is malware that has been used in targeted campaigns against members of the Tibetan Parliament in 2016.
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
KeyBoy uses custom SSL libraries to impersonate SSL in C2 traffic. |
| T1016 System Network Configuration Discovery |
KeyBoy can determine the public or WAN IP address for the system. |
| T1027.013 Encrypted/Encoded File |
In one version of KeyBoy, string obfuscation routines were used to hide many of the critical values referenced in the malware. |
| T1056.001 Keylogging |
KeyBoy installs a keylogger for intercepting credentials and keystrokes. |
| T1059.001 PowerShell |
KeyBoy uses PowerShell commands to download and execute payloads. |
| T1059.003 Windows Command Shell |
KeyBoy can launch interactive shells for communicating with the victim machine. |
| T1059.005 Visual Basic |
KeyBoy uses VBS scripts for installing files and performing execution. |
| T1059.006 Python |
KeyBoy uses Python scripts for installing files and performing execution. |
| T1070.006 Timestomp |
KeyBoy time-stomped its DLL in order to evade detection. |
| T1082 System Information Discovery |
KeyBoy can gather extended system information, such as information about the operating system and memory. |
| T1083 File and Directory Discovery |
KeyBoy has a command to launch a file browser or explorer on the system. |
| T1105 Ingress Tool Transfer |
KeyBoy has a download and upload functionality. |
| T1113 Screen Capture |
KeyBoy has a command to perform screen grabbing. |
| T1543.003 Windows Service |
KeyBoy installs a service pointing to a malicious DLL dropped to disk. |
| T1547.004 Winlogon Helper DLL |
KeyBoy issues the command |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.