Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, October 13). Dridex (Bugat v5) Botnet Takeover Operation. Retrieved May 31, 2019.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1090 Proxy |
MalwareDridex | Dridex contains a backconnect module for tunneling network traffic through a victim's computer. Infected computers become part of a P2P botnet that can relay C2 traffic to other infected peers. |
| T1185 Browser Session Hijacking |
MalwareDridex | Dridex can perform browser attacks via web injects to steal information such as credentials, certificates, and cookies. |
| T1219 Remote Access Tools |
MalwareDridex | Dridex contains a module for VNC. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.