Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
GoBear is installed through droppers masquerading as legitimate, signed software installers. |
| T1090 Proxy |
GoBear implements SOCKS5 proxy functionality. |
| T1553.002 Code Signing |
GoBear uses stolen legitimate code signing certificates for defense evasion. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.