Kaspersky Lab's Global Research & Analysis Team. (2017, October 16). BlackOasis APT and new targeted attacks leveraging zero-day exploit. Retrieved February 15, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
GroupBlackOasis | BlackOasis's first stage shellcode contains a NOP sled with alternative instructions that was likely designed to bypass antivirus tools. |
| T1027.002 Software Packing |
MalwareFinFisher | A FinFisher variant uses a custom packer. |
| T1518.001 Security Software Discovery |
MalwareFinFisher | FinFisher probes the system to check for antimalware processes. |
| T1574.001 DLL |
MalwareFinFisher | FinFisher uses DLL side-loading to load malicious programs. A FinFisher variant also uses DLL search order hijacking. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.