Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
CASTLETAP can execute a C2 command to transfer files from victim machines. |
| T1040 Network Sniffing |
CASTLETAP has the ability to create a raw promiscuous socket to sniff network traffic. |
| T1059.004 Unix Shell |
CASTLETAP has the ability to spawn BusyBox command shell in victim environments. |
| T1105 Ingress Tool Transfer |
CASTLETAP can transfer files to compromised network devices. |
| T1140 Deobfuscate/Decode Files or Information |
CASTLETAP can filter and deobfuscate an XOR encrypted activation string in the payload of an ICMP echo request. |
| T1205.002 Socket Filters |
CASTLETAP can listen for a specialized ICMP packet for activation on compromised network devices. |
| T1573.001 Symmetric Cryptography |
CASTLETAP can receive a 9-byte XOR encrypted activation string in the payload of an ICMP echo request packet. |
| T1573.002 Asymmetric Cryptography |
CASTLETAP can initiate a C2 connection over an SSL socket. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.