ATT&CKReferencesIntezer HiddenWasp Map 2019

Intezer HiddenWasp Map 2019

Sanmillan, I. (2019, May 29). HiddenWasp Malware Stings Targeted Linux Systems. Retrieved June 24, 2019.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1014
Rootkit
MalwareHiddenWasp

HiddenWasp uses a rootkit to hook and implement functions on the system.

T1027.013
Encrypted/Encoded File
MalwareHiddenWasp

HiddenWasp encrypts its configuration and payload.

T1037.004
RC Scripts
MalwareHiddenWasp

HiddenWasp installs reboot persistence by adding itself to /etc/rc.local.

T1059.003
Windows Command Shell
MalwareHiddenWasp

HiddenWasp uses a script to automate tasks on the victim's machine and to assist in execution.

T1095
Non-Application Layer Protocol
MalwareHiddenWasp

HiddenWasp communicates with a simple network protocol over TCP.

T1105
Ingress Tool Transfer
MalwareHiddenWasp

HiddenWasp downloads a tar compressed archive from a download server to the system.

T1136.001
Local Account
MalwareHiddenWasp

HiddenWasp creates a user account as a means to provide initial persistence to the compromised machine.

T1140
Deobfuscate/Decode Files or Information
MalwareHiddenWasp

HiddenWasp uses a cipher to implement a decoding function.

T1573.001
Symmetric Cryptography
MalwareHiddenWasp

HiddenWasp uses an RC4-like algorithm with an already computed PRGA generated key-stream for network communication.

T1574.006
Dynamic Linker Hijacking
MalwareHiddenWasp

HiddenWasp adds itself as a shared object to the LD_PRELOAD environment variable.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.