Rosenberg, J. (2018, June 14). MirageFox: APT15 Resurfaces With New Tools Based On Old Ones. Retrieved September 21, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareMirageFox | MirageFox can gather the username from the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareMirageFox | MirageFox has the capability to execute commands using cmd.exe. |
| T1082 System Information Discovery |
MalwareMirageFox | MirageFox can collect CPU and architecture information from the victim’s machine. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMirageFox | MirageFox has a function for decrypting data containing C2 configuration information. |
| T1574.001 DLL |
MalwareMirageFox | MirageFox is likely loaded via DLL hijacking into a legitimate McAfee binary. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.