Kaspersky Lab's Global Research & Analysis Team. (2015, August 10). Darkhotel's attacks in 2015. Retrieved November 2, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupDarkhotel | Darkhotel has collected the IP address and network adapter information from the victim’s machine. |
| T1027.013 Encrypted/Encoded File |
GroupDarkhotel | Darkhotel has obfuscated code using RC4, XOR, and RSA. |
| T1057 Process Discovery |
GroupDarkhotel | Darkhotel malware can collect a list of running processes on a system. |
| T1059.003 Windows Command Shell |
GroupDarkhotel | Darkhotel has dropped an mspaint.lnk shortcut to disk which launches a shell script that downloads and executes a file. |
| T1082 System Information Discovery |
GroupDarkhotel | Darkhotel has collected the hostname, OS version, service pack version, and the processor architecture from the victim’s machine. |
| T1140 Deobfuscate/Decode Files or Information |
GroupDarkhotel | Darkhotel has decrypted strings and imports using RC4 during execution. |
| T1204.002 Malicious File |
GroupDarkhotel | Darkhotel has sent spearphishing emails in an attempt to lure users into clicking on a malicious attachments. |
| T1518.001 Security Software Discovery |
GroupDarkhotel | Darkhotel has searched for anti-malware strings and anti-virus processes running on the system. |
| T1553.002 Code Signing |
GroupDarkhotel | Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them. |
| T1566.001 Spearphishing Attachment |
GroupDarkhotel | Darkhotel has sent spearphishing emails with malicious RAR and .LNK attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.