Sanmillan, I. (2019, May 29). HiddenWasp Malware Stings Targeted Linux Systems. Retrieved June 24, 2019.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
MalwareHiddenWasp | HiddenWasp uses a rootkit to hook and implement functions on the system. |
| T1027.013 Encrypted/Encoded File |
MalwareHiddenWasp | HiddenWasp encrypts its configuration and payload. |
| T1037.004 RC Scripts |
MalwareHiddenWasp | HiddenWasp installs reboot persistence by adding itself to |
| T1059.003 Windows Command Shell |
MalwareHiddenWasp | HiddenWasp uses a script to automate tasks on the victim's machine and to assist in execution. |
| T1095 Non-Application Layer Protocol |
MalwareHiddenWasp | HiddenWasp communicates with a simple network protocol over TCP. |
| T1105 Ingress Tool Transfer |
MalwareHiddenWasp | HiddenWasp downloads a tar compressed archive from a download server to the system. |
| T1136.001 Local Account |
MalwareHiddenWasp | HiddenWasp creates a user account as a means to provide initial persistence to the compromised machine. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHiddenWasp | HiddenWasp uses a cipher to implement a decoding function. |
| T1573.001 Symmetric Cryptography |
MalwareHiddenWasp | HiddenWasp uses an RC4-like algorithm with an already computed PRGA generated key-stream for network communication. |
| T1574.006 Dynamic Linker Hijacking |
MalwareHiddenWasp | HiddenWasp adds itself as a shared object to the LD_PRELOAD environment variable. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.