Chen, J. et al. (2019, November). Operation ENDTRADE: TICK’s Multi-Stage Backdoors for Attacking Industries and Stealing Classified Data. Retrieved June 9, 2020.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used TROJ_GETVERSION to discover system services. |
| T1016 System Network Configuration Discovery |
Malwaredown_new | down_new has the ability to identify the MAC address of a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareAvenger | Avenger can identify the domain of the compromised host. |
| T1027.001 Binary Padding |
GroupBRONZE BUTLER | BRONZE BUTLER downloader code has included "0" characters at the end of the file to inflate the file size in a likely attempt to evade anti-virus detection. |
| T1027.003 Steganography |
MalwareBBK | BBK can extract a malicious Portable Executable (PE) from a photo. |
| T1027.003 Steganography |
GroupBRONZE BUTLER | BRONZE BUTLER has used steganography in multiple operations to conceal malicious payloads. |
| T1027.003 Steganography |
MalwareABK | ABK can extract a malicious Portable Executable (PE) from a photo. |
| T1027.003 Steganography |
MalwareAvenger | Avenger can extract backdoor malware from downloaded images. |
| T1027.003 Steganography |
Malwarebuild_downer | build_downer can extract malware from a downloaded JPEG. |
| T1027.013 Encrypted/Encoded File |
MalwareAvenger | Avenger has the ability to XOR encrypt files to be sent to C2. |
| T1036 Masquerading |
GroupBRONZE BUTLER | BRONZE BUTLER has masked executables with document file icons including Word and Adobe PDF. |
| T1036.002 Right-to-Left Override |
GroupBRONZE BUTLER | BRONZE BUTLER has used Right-to-Left Override to deceive victims into executing several strains of malware. |
| T1036.004 Masquerade Task or Service |
Malwarebuild_downer | build_downer has added itself to the Registry Run key as "NVIDIA" to appear legitimate. |
| T1055 Process Injection |
MalwareABK | ABK has the ability to inject shellcode into svchost.exe. |
| T1055 Process Injection |
MalwareBBK | BBK has the ability to inject shellcode into svchost.exe. |
| T1055 Process Injection |
MalwareAvenger | Avenger has the ability to inject shellcode into svchost.exe. |
| T1057 Process Discovery |
Malwaredown_new | down_new has the ability to list running processes on a compromised host. |
| T1057 Process Discovery |
MalwareAvenger | Avenger has the ability to use Tasklist to identify running processes. |
| T1059.003 Windows Command Shell |
MalwareBBK | BBK has the ability to use cmd to run a Portable Executable (PE) on the compromised host. |
| T1059.003 Windows Command Shell |
MalwareABK | ABK has the ability to use cmd to run a Portable Executable (PE) on the compromised host. |
| T1059.005 Visual Basic |
GroupBRONZE BUTLER | BRONZE BUTLER has used VBS and VBE scripts for execution. |
| T1059.006 Python |
GroupBRONZE BUTLER | BRONZE BUTLER has made use of Python-based remote access tools. |
| T1071.001 Web Protocols |
MalwareABK | ABK has the ability to use HTTP in communications with C2. |
| T1071.001 Web Protocols |
MalwareBBK | BBK has the ability to use HTTP in communications with C2. |
| T1071.001 Web Protocols |
MalwareAvenger | Avenger has the ability to use HTTP in communication with C2. |
| T1071.001 Web Protocols |
Malwaredown_new | down_new has the ability to use HTTP in C2 communications. |
| T1082 System Information Discovery |
MalwareAvenger | Avenger has the ability to identify the OS architecture on a compromised host. |
| T1083 File and Directory Discovery |
MalwareAvenger | Avenger has the ability to browse files in directories such as Program Files and the Desktop. |
| T1083 File and Directory Discovery |
Malwaredown_new | down_new has the ability to list the directories on a compromised host. |
| T1105 Ingress Tool Transfer |
Malwarebuild_downer | build_downer has the ability to download files from C2 to the infected host. |
| T1105 Ingress Tool Transfer |
MalwareBBK | BBK has the ability to download files from C2 to the infected host. |
| T1105 Ingress Tool Transfer |
Malwaredown_new | down_new has the ability to download files to the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareAvenger | Avenger has the ability to download files from C2 to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareABK | ABK has the ability to download files from C2. |
| T1106 Native API |
MalwareBBK | BBK has the ability to use the |
| T1106 Native API |
Malwarebuild_downer | build_downer has the ability to use the |
| T1113 Screen Capture |
GroupBRONZE BUTLER | BRONZE BUTLER has used a tool to capture screenshots. |
| T1124 System Time Discovery |
Malwarebuild_downer | build_downer has the ability to determine the local time to ensure malware installation only happens during the hours that the infected system is active. |
| T1132.001 Standard Encoding |
Malwaredown_new | down_new has the ability to base64 encode C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBBK | BBK has the ability to decrypt AES encrypted payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAvenger | Avenger has the ability to decrypt files downloaded from C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareABK | ABK has the ability to decrypt AES encrypted payloads. |
| T1203 Exploitation for Client Execution |
GroupBRONZE BUTLER | BRONZE BUTLER has exploited Microsoft Office vulnerabilities CVE-2014-4114, CVE-2018-0802, and CVE-2018-0798 for execution. |
| T1204.002 Malicious File |
GroupBRONZE BUTLER | BRONZE BUTLER has attempted to get users to launch malicious Microsoft Word attachments delivered via spearphishing emails. |
| T1518 Software Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used tools to enumerate software installed on an infected host. |
| T1518 Software Discovery |
Malwaredown_new | down_new has the ability to gather information on installed applications. |
| T1518.001 Security Software Discovery |
Malwaredown_new | down_new has the ability to detect anti-virus products and processes on a compromised host. |
| T1518.001 Security Software Discovery |
MalwareAvenger | Avenger has the ability to identify installed anti-virus products on a compromised host. |
| T1518.001 Security Software Discovery |
MalwareABK | ABK has the ability to identify the installed anti-virus product on the compromised host. |
| T1518.001 Security Software Discovery |
Malwarebuild_downer | build_downer has the ability to detect if the infected host is running an anti-virus process. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.