Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
RegDuke can use control-flow flattening or the commercially available .NET Reactor for obfuscation. |
| T1027.003 Steganography |
RegDuke can hide data in images, including use of the Least Significant Bit (LSB). |
| T1027.011 Fileless Storage |
RegDuke can store its encryption key in the Registry. |
| T1059.001 PowerShell |
RegDuke can extract and execute PowerShell scripts from C2 communications. |
| T1102.002 Bidirectional Communication |
RegDuke can use Dropbox as its C2 server. |
| T1105 Ingress Tool Transfer |
RegDuke can download files from C2. |
| T1112 Modify Registry |
RegDuke can create seemingly legitimate Registry key to store its encryption key. |
| T1140 Deobfuscate/Decode Files or Information |
RegDuke can decrypt strings with a key either stored in the Registry or hardcoded in the code. |
| T1546.003 Windows Management Instrumentation Event Subscription |
RegDuke can persist using a WMI consumer that is launched every time a process named WINWORD.EXE is started. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.