ATT&CKReferencesSecurelist Darkhotel Aug 2015

Securelist Darkhotel Aug 2015

Kaspersky Lab's Global Research & Analysis Team. (2015, August 10). Darkhotel's attacks in 2015. Retrieved November 2, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupDarkhotel

Darkhotel has collected the IP address and network adapter information from the victim’s machine.

T1027.013
Encrypted/Encoded File
GroupDarkhotel

Darkhotel has obfuscated code using RC4, XOR, and RSA.

T1057
Process Discovery
GroupDarkhotel

Darkhotel malware can collect a list of running processes on a system.

T1059.003
Windows Command Shell
GroupDarkhotel

Darkhotel has dropped an mspaint.lnk shortcut to disk which launches a shell script that downloads and executes a file.

T1082
System Information Discovery
GroupDarkhotel

Darkhotel has collected the hostname, OS version, service pack version, and the processor architecture from the victim’s machine.

T1140
Deobfuscate/Decode Files or Information
GroupDarkhotel

Darkhotel has decrypted strings and imports using RC4 during execution.

T1204.002
Malicious File
GroupDarkhotel

Darkhotel has sent spearphishing emails in an attempt to lure users into clicking on a malicious attachments.

T1518.001
Security Software Discovery
GroupDarkhotel

Darkhotel has searched for anti-malware strings and anti-virus processes running on the system.

T1553.002
Code Signing
GroupDarkhotel

Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them.

T1566.001
Spearphishing Attachment
GroupDarkhotel

Darkhotel has sent spearphishing emails with malicious RAR and .LNK attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.