Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
Malwareyty | yty collects files with the following extensions: .ppt, .pptx, .pdf, .doc, .docx, .xls, .xlsx, .docm, .rtf, .inp, .xlsm, .csv, .odt, .pps, .vcf and sends them back to the C2 server. |
| T1016 System Network Configuration Discovery |
Malwareyty | yty runs |
| T1018 Remote System Discovery |
Malwareyty | yty uses the |
| T1027.002 Software Packing |
Malwareyty | yty packs a plugin with UPX. |
| T1027.016 Junk Code Insertion |
Malwareyty | yty contains junk code in its binary, likely to confuse malware analysts. |
| T1033 System Owner/User Discovery |
Malwareyty | yty collects the victim’s username. |
| T1053.005 Scheduled Task |
Malwareyty | yty establishes persistence by creating a scheduled task with the command |
| T1056.001 Keylogging |
Malwareyty | yty uses a keylogger plugin to gather keystrokes. |
| T1057 Process Discovery |
Malwareyty | yty gets an output of running processes using the |
| T1082 System Information Discovery |
Malwareyty | yty gathers the computer name, CPU information, Microsoft Windows version, and runs the command |
| T1083 File and Directory Discovery |
Malwareyty | yty gathers information on victim’s drives and has a plugin for document listing. |
| T1102.002 Bidirectional Communication |
Malwareyty | yty communicates to the C2 server by retrieving a Google Doc. |
| T1113 Screen Capture |
Malwareyty | yty collects screenshots of the victim machine. |
| T1497.001 System Checks |
Malwareyty | yty has some basic anti-sandbox detection that tries to detect Virtual PC, Sandboxie, and VMware. |
| T1680 Local Storage Discovery |
Malwareyty | yty gathers the the serial number of the main disk volume. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.