Malware.View on attack.mitre.org
StrongPity is an information stealing malware used by PROMETHIUM.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
StrongPity can identify the IP address of a compromised host. |
| T1020 Automated Exfiltration |
StrongPity can automatically exfiltrate collected documents to the C2 server. |
| T1027.013 Encrypted/Encoded File |
StrongPity has used encrypted strings in its dropper component. |
| T1036.004 Masquerade Task or Service |
StrongPity has named services to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
StrongPity has been bundled with legitimate software installation files for disguise. |
| T1041 Exfiltration Over C2 Channel |
StrongPity can exfiltrate collected documents through C2 channels. |
| T1057 Process Discovery |
StrongPity can determine if a user is logged in by checking to see if explorer.exe is running. |
| T1059.001 PowerShell |
StrongPity can use PowerShell to add files to the Windows Defender exclusions list. |
| T1070.004 File Deletion |
StrongPity can delete previously exfiltrated files from the compromised host. |
| T1071.001 Web Protocols |
StrongPity can use HTTP and HTTPS in C2 communications. |
| T1083 File and Directory Discovery |
StrongPity can parse the hard drive on a compromised host to identify specific file extensions. |
| T1090.003 Multi-hop Proxy |
StrongPity can use multiple layers of proxy servers to hide terminal nodes in its infrastructure. |
| T1105 Ingress Tool Transfer |
StrongPity can download files to specified targets. |
| T1119 Automated Collection |
StrongPity has a file searcher component that can automatically collect and archive files based on a predefined list of file extensions. |
| T1204.002 Malicious File |
StrongPity has been executed via compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.