Malware.View on attack.mitre.org
Heyoka Backdoor is a custom backdoor--based on the Heyoka open source exfiltration tool--that has been used by Aoqin Dragon since at least 2013.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
Heyoka Backdoor can check if it is running as a service on a compromised host. |
| T1027.013 Encrypted/Encoded File |
Heyoka Backdoor can encrypt its payload. |
| T1036.004 Masquerade Task or Service |
Heyoka Backdoor has been named `srvdll.dll` to appear as a legitimate service. |
| T1055.001 Dynamic-link Library Injection |
Heyoka Backdoor can inject a DLL into rundll32.exe for execution. |
| T1057 Process Discovery |
Heyoka Backdoor can gather process information. |
| T1070.004 File Deletion |
Heyoka Backdoor has the ability to delete folders and files from a targeted system. |
| T1071.004 DNS |
Heyoka Backdoor can use DNS tunneling for C2 communications. |
| T1083 File and Directory Discovery |
Heyoka Backdoor has the ability to search the compromised host for files. |
| T1120 Peripheral Device Discovery |
Heyoka Backdoor can identify removable media attached to victim's machines. |
| T1140 Deobfuscate/Decode Files or Information |
Heyoka Backdoor can decrypt its payload prior to execution. |
| T1204.002 Malicious File |
Heyoka Backdoor has been spread through malicious document lures. |
| T1218.011 Rundll32 |
Heyoka Backdoor can use rundll32.exe to gain execution. |
| T1547.001 Registry Run Keys / Startup Folder |
Heyoka Backdoor can establish persistence with the auto start function including using the value `EverNoteTrayUService`. |
| T1572 Protocol Tunneling |
Heyoka Backdoor can use spoofed DNS requests to create a bidirectional tunnel between a compromised host and its C2 servers. |
| T1680 Local Storage Discovery |
Heyoka Backdoor can enumerate drives on a compromised host. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.