Minerva Labs LTD and ClearSky Cyber Security. (2015, November 23). CopyKittens Attack Group. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareMatryoshka | Matryoshka obfuscates API function names using a substitute cipher combined with Base64 encoding. |
| T1053.005 Scheduled Task |
MalwareMatryoshka | Matryoshka can establish persistence by adding a Scheduled Task named "Microsoft Boost Kernel Optimization". |
| T1055.001 Dynamic-link Library Injection |
MalwareMatryoshka | Matryoshka uses reflective DLL injection to inject the malicious library and execute the RAT. |
| T1056.001 Keylogging |
MalwareMatryoshka | Matryoshka is capable of keylogging. |
| T1071.004 DNS |
MalwareMatryoshka | Matryoshka uses DNS for C2. |
| T1113 Screen Capture |
MalwareMatryoshka | Matryoshka is capable of performing screen captures. |
| T1218.011 Rundll32 |
MalwareMatryoshka | Matryoshka uses rundll32.exe in a Registry Run key value for execution as part of its persistence mechanism. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMatryoshka | Matryoshka can establish persistence by adding Registry Run keys. |
| T1555 Credentials from Password Stores |
MalwareMatryoshka | Matryoshka is capable of stealing Outlook passwords. |
| T1560.003 Archive via Custom Method |
GroupCopyKittens | CopyKittens encrypts data with a substitute cipher prior to exfiltration. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.