Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Gomir collects network information on infected systems such as listing interface names, MAC and IP addresses, and IPv6 addresses. |
| T1018 Remote System Discovery |
Gomir probes arbitrary network endpoints for TCP connectivity. |
| T1053.003 Cron |
Gomir will configure a crontab for process execution to start the backdoor on reboot if it is not initially running under group 0 privileges. |
| T1059.004 Unix Shell |
Gomir reads command line arguments and parses them for functionality when executed from a Linux shell, and can execute arbitrary strings passed to it as shell commands. |
| T1069.001 Local Groups |
Gomir checks the effective group ID of its process when initially executed to determine if it is in group 0, denoting superuser privileges in Linux environments. |
| T1070.004 File Deletion |
Gomir deletes its original executable and terminates its original process after creating a systemd service. |
| T1071.001 Web Protocols |
Gomir periodically communicates to its command and control infrastructure through HTTP POST requests. |
| T1082 System Information Discovery |
Gomir collects information on infected systems such as hostname, username, CPU, and RAM information. |
| T1083 File and Directory Discovery |
Gomir collects information about directory and file structures, including total number of subdirectories, total number of files, and total size of files on infected systems. |
| T1090.001 Internal Proxy |
Gomir can start a reverse proxy to initiate connections to arbitrary endpoints in victim networks. |
| T1132.001 Standard Encoding |
Gomir uses Base64-encoded content in HTTP communications to command and control infrastructure. |
| T1543.002 Systemd Service |
Gomir creates a systemd service named `syslogd` for persistence. |
| T1573 Encrypted Channel |
Gomir uses a custom encryption algorithm for content sent to command and control infrastructure. |
| T1573.002 Asymmetric Cryptography |
Gomir uses reverse proxy functionality that employs SSL to encrypt communications. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.