Malware.View on attack.mitre.org
PolyglotDuke is a downloader that has been used by APT29 since at least 2013. PolyglotDuke has been used to drop MiniDuke.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
PolyglotDuke can custom encrypt strings. |
| T1027.003 Steganography |
PolyglotDuke can use steganography to hide C2 information in images. |
| T1027.011 Fileless Storage |
PolyglotDuke can store encrypted JSON configuration files in the Registry. |
| T1071.001 Web Protocols |
PolyglotDuke has has used HTTP GET requests in C2 communications. |
| T1102.001 Dead Drop Resolver |
PolyglotDuke can use Twitter, Reddit, Imgur and other websites to get a C2 URL. |
| T1105 Ingress Tool Transfer |
PolyglotDuke can retrieve payloads from the C2 server. |
| T1106 Native API |
PolyglotDuke can use |
| T1112 Modify Registry |
PolyglotDuke can write encrypted JSON configuration files to the Registry. |
| T1140 Deobfuscate/Decode Files or Information |
PolyglotDuke can use a custom algorithm to decrypt strings used by the malware. |
| T1218.011 Rundll32 |
PolyglotDuke can be executed using rundll32.exe. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.