ATT&CKReferencesSecurelist BlackOasis Oct 2017

Securelist BlackOasis Oct 2017

Kaspersky Lab's Global Research & Analysis Team. (2017, October 16). BlackOasis APT and new targeted attacks leveraging zero-day exploit. Retrieved February 15, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupBlackOasis

BlackOasis's first stage shellcode contains a NOP sled with alternative instructions that was likely designed to bypass antivirus tools.

T1027.002
Software Packing
MalwareFinFisher

A FinFisher variant uses a custom packer.

T1518.001
Security Software Discovery
MalwareFinFisher

FinFisher probes the system to check for antimalware processes.

T1574.001
DLL
MalwareFinFisher

FinFisher uses DLL side-loading to load malicious programs. A FinFisher variant also uses DLL search order hijacking.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.