Malware.View on attack.mitre.org
Hannotog is a type of backdoor malware uniquely assoicated with Lotus Blossom operations since at least 2022.
| Technique | Procedure example |
|---|---|
| T1020 Automated Exfiltration |
Hannotog can upload encyrpted data for exfiltration. |
| T1059.003 Windows Command Shell |
Hannotog can execute various `cmd.exe /c %s` commands. |
| T1105 Ingress Tool Transfer |
Hannotog can download additional files to the victim machine. |
| T1489 Service Stop |
Hannotog can stop Windows services. |
| T1543.003 Windows Service |
Hannotog creates a new service for persistence. |
| T1571 Non-Standard Port |
Hannotog uses non-standard listening ports, such as UDP 5900, for command and control purposes. |
| T1686 Disable or Modify System Firewall |
Hannotog can modify local firewall settings via `netsh` commands to open a listening UDP port. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.