Malware.View on attack.mitre.org
WarzoneRAT is a malware-as-a-service remote access tool (RAT) written in C++ that has been publicly available for purchase since at least late 2018.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
WarzoneRAT can collect data from a compromised host. |
| T1014 Rootkit |
WarzoneRAT can include a rootkit to hide processes, files, and startup. |
| T1021.001 Remote Desktop Protocol |
WarzoneRAT has the ability to control an infected PC using RDP. |
| T1021.005 VNC |
WarzoneRAT has the ability of performing remote desktop access via a VNC console. |
| T1041 Exfiltration Over C2 Channel |
WarzoneRAT can send collected victim data to its C2 server. |
| T1055 Process Injection |
WarzoneRAT has the ability to inject malicious DLLs into a specific process for privilege escalation. |
| T1056.001 Keylogging |
WarzoneRAT has the capability to install a live and offline keylogger, including through the use of the `GetAsyncKeyState` Windows API. |
| T1057 Process Discovery |
WarzoneRAT can obtain a list of processes on a compromised host. |
| T1059.001 PowerShell |
WarzoneRAT can use PowerShell to download files and execute commands. |
| T1059.003 Windows Command Shell |
WarzoneRAT can use `cmd.exe` to execute malicious code. |
| T1082 System Information Discovery |
WarzoneRAT can collect compromised host information, including OS version, PC name, RAM size, and CPU details. |
| T1083 File and Directory Discovery |
WarzoneRAT can enumerate directories on a compromise host. |
| T1090 Proxy |
WarzoneRAT has the capability to act as a reverse proxy. |
| T1095 Non-Application Layer Protocol |
WarzoneRAT can communicate with its C2 server via TCP over port 5200. |
| T1105 Ingress Tool Transfer |
WarzoneRAT can download and execute additional files. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.