Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Kessel has collected the DNS address of the infected host. |
| T1027.013 Encrypted/Encoded File |
Kessel's configuration is hardcoded and RC4 encrypted within the binary. |
| T1030 Data Transfer Size Limits |
Kessel can split the data to be exilftrated into chunks that will fit in subdomains of DNS queries. |
| T1041 Exfiltration Over C2 Channel |
Kessel has exfiltrated information gathered from the infected system to the C2 server. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Kessel can exfiltrate credentials and other information via HTTP POST request, TCP, and DNS. |
| T1059 Command and Scripting Interpreter |
Kessel can create a reverse shell between the infected host and a specified system. |
| T1082 System Information Discovery |
Kessel has collected the system architecture, OS version, and MAC address information. |
| T1090 Proxy |
Kessel can use a proxy during exfiltration if set in the configuration. |
| T1105 Ingress Tool Transfer |
Kessel can download additional modules from the C2 server. |
| T1132.001 Standard Encoding |
Kessel has exfiltrated data via hexadecimal-encoded subdomain fields of DNS queries. |
| T1140 Deobfuscate/Decode Files or Information |
Kessel has decrypted the binary's configuration once the |
| T1554 Compromise Host Software Binary |
Kessel has maliciously altered the OpenSSH binary on targeted systems to create a backdoor. |
| T1556 Modify Authentication Process |
Kessel has trojanized the <sode>ssh_login</code> and |
| T1560 Archive Collected Data |
Kessel can RC4-encrypt credentials before sending to the C2. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.