Malware.View on attack.mitre.org
AuTo Stealer is malware written in C++ has been used by SideCopy since at least December 2021 to target government agencies and personnel in India and Afghanistan.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
AuTo Stealer can collect data such as PowerPoint files, Word documents, Excel files, PDF files, text files, database files, and image files from an infected machine. |
| T1033 System Owner/User Discovery |
AuTo Stealer has the ability to collect the username from an infected host. |
| T1041 Exfiltration Over C2 Channel |
AuTo Stealer can exfiltrate data over actor-controlled C2 servers via HTTP or TCP. |
| T1059.003 Windows Command Shell |
AuTo Stealer can use `cmd.exe` to execute a created batch file. |
| T1071.001 Web Protocols |
AuTo Stealer can use HTTP to communicate with its C2 servers. |
| T1074.001 Local Data Staging |
AuTo Stealer can store collected data from an infected host to a file named `Hostname_UserName.txt` prior to exfiltration. |
| T1082 System Information Discovery |
AuTo Stealer has the ability to collect the hostname and OS information from an infected host. |
| T1095 Non-Application Layer Protocol |
AuTo Stealer can use TCP to communicate with command and control servers. |
| T1518.001 Security Software Discovery |
AuTo Stealer has the ability to collect information about installed AV products from an infected host. |
| T1547.001 Registry Run Keys / Startup Folder |
AuTo Stealer can place malicious executables in a victim's AutoRun registry key or StartUp directory, depending on the AV product installed, to maintain persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.