NSA/FBI. (2020, August). Russian GRU 85th GTsSS Deploys Previously Undisclosed Drovorub Malware. Retrieved August 25, 2020.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareDrovorub | Drovorub can transfer files from the victim machine. |
| T1014 Rootkit |
MalwareDrovorub | Drovorub has used a kernel module rootkit to hide processes, files, executables, and network artifacts from user space view. |
| T1027 Obfuscated Files or Information |
MalwareDrovorub | Drovorub has used XOR encrypted payloads in WebSocket client to server messages. |
| T1041 Exfiltration Over C2 Channel |
MalwareDrovorub | Drovorub can exfiltrate files over C2 infrastructure. |
| T1059.004 Unix Shell |
MalwareDrovorub | Drovorub can execute arbitrary commands as root on a compromised system. |
| T1070.004 File Deletion |
MalwareDrovorub | Drovorub can delete specific files from a compromised host. |
| T1071.001 Web Protocols |
MalwareDrovorub | Drovorub can use the WebSocket protocol and has initiated communication with C2 servers with an HTTP Upgrade request. |
| T1090.001 Internal Proxy |
MalwareDrovorub | Drovorub can use a port forwarding rule on its agent module to relay network traffic through the client module to a remote host on the same network. |
| T1095 Non-Application Layer Protocol |
MalwareDrovorub | Drovorub can use TCP to communicate between its agent and client modules. |
| T1105 Ingress Tool Transfer |
MalwareDrovorub | Drovorub can download files to a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDrovorub | Drovorub has de-obsfuscated XOR encrypted payloads in WebSocket messages. |
| T1547.006 Kernel Modules and Extensions |
MalwareDrovorub | Drovorub can use kernel modules to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.