Malware.View on attack.mitre.org
SMOKEDHAM is a Powershell-based .NET backdoor that was first reported in May 2021; it has been used by at least one ransomware-as-a-service affiliate.
| Technique | Procedure example |
|---|---|
| T1027.009 Embedded Payloads |
The SMOKEDHAM source code is embedded in the dropper as an encrypted string. |
| T1033 System Owner/User Discovery |
SMOKEDHAM has used |
| T1041 Exfiltration Over C2 Channel |
SMOKEDHAM has exfiltrated data to its C2 server. |
| T1056.001 Keylogging |
SMOKEDHAM can continuously capture keystrokes. |
| T1059.001 PowerShell |
SMOKEDHAM can execute Powershell commands sent from its C2 server. |
| T1071.001 Web Protocols |
SMOKEDHAM has communicated with its C2 servers via HTTPS and HTTP POST requests. |
| T1082 System Information Discovery |
SMOKEDHAM has used the |
| T1087.001 Local Account |
SMOKEDHAM has used |
| T1090.004 Domain Fronting |
SMOKEDHAM has used a fronted domain to obfuscate its hard-coded C2 server domain. |
| T1098.007 Additional Local or Domain Groups |
SMOKEDHAM has added user accounts to local Admin groups. |
| T1102 Web Service |
SMOKEDHAM has used Google Drive and Dropbox to host files downloaded by victims via malicious links. |
| T1105 Ingress Tool Transfer |
SMOKEDHAM has used Powershell to download UltraVNC and ngrok from third-party file sharing sites. |
| T1112 Modify Registry |
SMOKEDHAM has modified registry keys for persistence, to enable credential caching for credential access, and to facilitate lateral movement via RDP. |
| T1113 Screen Capture |
SMOKEDHAM can capture screenshots of the victim’s desktop. |
| T1132.001 Standard Encoding |
SMOKEDHAM has encoded its C2 traffic with Base64. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.