Malware.View on attack.mitre.org
Avenger is a downloader that has been used by BRONZE BUTLER since at least 2019.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Avenger can identify the domain of the compromised host. |
| T1027.003 Steganography |
Avenger can extract backdoor malware from downloaded images. |
| T1027.013 Encrypted/Encoded File |
Avenger has the ability to XOR encrypt files to be sent to C2. |
| T1055 Process Injection |
Avenger has the ability to inject shellcode into svchost.exe. |
| T1057 Process Discovery |
Avenger has the ability to use Tasklist to identify running processes. |
| T1071.001 Web Protocols |
Avenger has the ability to use HTTP in communication with C2. |
| T1082 System Information Discovery |
Avenger has the ability to identify the OS architecture on a compromised host. |
| T1083 File and Directory Discovery |
Avenger has the ability to browse files in directories such as Program Files and the Desktop. |
| T1105 Ingress Tool Transfer |
Avenger has the ability to download files from C2 to a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
Avenger has the ability to decrypt files downloaded from C2. |
| T1518.001 Security Software Discovery |
Avenger has the ability to identify installed anti-virus products on a compromised host. |
| T1680 Local Storage Discovery |
Avenger has the ability to identify the host volume ID. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.