Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
MalwareRevenge RAT | Revenge RAT has a plugin for credential harvesting. |
| T1016 System Network Configuration Discovery |
MalwareRevenge RAT | Revenge RAT collects the IP address and MAC address from the system. |
| T1021.001 Remote Desktop Protocol |
MalwareRevenge RAT | Revenge RAT has a plugin to perform RDP access. |
| T1027.002 Software Packing |
GroupThe White Company | The White Company has obfuscated their payloads through packing. |
| T1033 System Owner/User Discovery |
MalwareRevenge RAT | Revenge RAT gathers the username from the system. |
| T1056.001 Keylogging |
MalwareRevenge RAT | Revenge RAT has a plugin for keylogging. |
| T1070.004 File Deletion |
GroupThe White Company | The White Company has the ability to delete its malware entirely from the target system. |
| T1082 System Information Discovery |
MalwareRevenge RAT | Revenge RAT collects the CPU information, OS information, and system language. |
| T1105 Ingress Tool Transfer |
MalwareRevenge RAT | Revenge RAT has the ability to upload and download files. |
| T1113 Screen Capture |
MalwareRevenge RAT | Revenge RAT has a plugin for screen capture. |
| T1123 Audio Capture |
MalwareRevenge RAT | Revenge RAT has a plugin for microphone interception. |
| T1124 System Time Discovery |
GroupThe White Company | The White Company has checked the current date on the victim system. |
| T1125 Video Capture |
MalwareRevenge RAT | Revenge RAT has the ability to access the webcam. |
| T1132.001 Standard Encoding |
MalwareRevenge RAT | Revenge RAT uses Base64 to encode information sent to the C2 server. |
| T1203 Exploitation for Client Execution |
GroupThe White Company | The White Company has taken advantage of a known vulnerability in Microsoft Word (CVE 2012-0158) to execute code. |
| T1204.002 Malicious File |
GroupThe White Company | The White Company has used phishing lure documents that trick users into opening them and infecting their computers. |
| T1518.001 Security Software Discovery |
GroupThe White Company | The White Company has checked for specific antivirus products on the target’s computer, including Kaspersky, Quick Heal, AVG, BitDefender, Avira, Sophos, Avast!, and ESET. |
| T1547.004 Winlogon Helper DLL |
MalwareRevenge RAT | Revenge RAT creates a Registry key at |
| T1566.001 Spearphishing Attachment |
GroupThe White Company | The White Company has sent phishing emails with malicious Microsoft Word attachments to victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.