ATT&CKReferencesTrendMicro Lazarus Nov 2018

TrendMicro Lazarus Nov 2018

Trend Micro. (2018, November 20). Lazarus Continues Heists, Mounts Attacks on Financial Organizations in Latin America. Retrieved December 3, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareAuditCred

AuditCred encrypts the configuration.

T1055
Process Injection
MalwareAuditCred

AuditCred can inject code from files to other running processes.

T1059.003
Windows Command Shell
MalwareAuditCred

AuditCred can open a reverse shell on the system to execute commands.

T1070.004
File Deletion
MalwareAuditCred

AuditCred can delete files from the system.

T1083
File and Directory Discovery
MalwareAuditCred

AuditCred can search through folders and files on the system.

T1090
Proxy
MalwareAuditCred

AuditCred can utilize proxy for communications.

T1105
Ingress Tool Transfer
MalwareAuditCred

AuditCred can download files and additional malware.

T1140
Deobfuscate/Decode Files or Information
MalwareAuditCred

AuditCred uses XOR and RC4 to perform decryption on the code functions.

T1543.003
Windows Service
MalwareAuditCred

AuditCred is installed as a new service on the system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.