Ilascu, I. (2020, December 14). Hacking group’s new malware abuses Google and Facebook services. Retrieved December 28, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareSharpStage | SharpStage can use WMI for execution. |
| T1059.001 PowerShell |
MalwareSharpStage | SharpStage can execute arbitrary commands with PowerShell. |
| T1059.003 Windows Command Shell |
MalwareSharpStage | SharpStage can execute arbitrary commands with the command line. |
| T1059.003 Windows Command Shell |
MalwareDropBook | DropBook can execute arbitrary shell commands on the victims' machines. |
| T1082 System Information Discovery |
MalwareSharpStage | SharpStage has checked the system settings to see if Arabic is the configured language. |
| T1083 File and Directory Discovery |
MalwareDropBook | DropBook can collect the names of all files and folders in the Program Files directories. |
| T1102 Web Service |
MalwareDropBook | DropBook can communicate with its operators by exploiting the Simplenote, DropBox, and the social media platform, Facebook, where it can create fake accounts to control the backdoor and receive instructions. |
| T1105 Ingress Tool Transfer |
MalwareDropBook | DropBook can download and execute additional files. |
| T1105 Ingress Tool Transfer |
MalwareSharpStage | SharpStage has the ability to download and execute additional payloads via a DropBox API. |
| T1113 Screen Capture |
MalwareSharpStage | SharpStage has the ability to capture the victim's screen. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSharpStage | SharpStage has decompressed data received from the C2 server. |
| T1567 Exfiltration Over Web Service |
MalwareDropBook | DropBook has used legitimate web services to exfiltrate data. |
| T1614.001 System Language Discovery |
MalwareDropBook | DropBook has checked for the presence of Arabic language in the infected machine's settings. |
| T1614.001 System Language Discovery |
MalwareSharpStage | SharpStage has been used to target Arabic-speaking users and used code that checks if the compromised machine has the Arabic language installed. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.