ATT&CKReferencesZscaler Kasidet

Zscaler Kasidet

Yadav, A., et al. (2016, January 29). Malicious Office files dropping Kasidet and Dridex. Retrieved March 24, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareKasidet

Kasidet has the ability to initiate keylogging.

T1057
Process Discovery
MalwareKasidet

Kasidet has the ability to search for a given process name in processes currently running in the system.

T1059.003
Windows Command Shell
MalwareKasidet

Kasidet can execute commands using cmd.exe.

T1082
System Information Discovery
MalwareKasidet

Kasidet has the ability to obtain a victim's system name and operating system version.

T1083
File and Directory Discovery
MalwareKasidet

Kasidet has the ability to search for a given filename on a victim.

T1105
Ingress Tool Transfer
MalwareKasidet

Kasidet has the ability to download and execute additional files.

T1113
Screen Capture
MalwareKasidet

Kasidet has the ability to initiate keylogging and screen captures.

T1518.001
Security Software Discovery
MalwareKasidet

Kasidet has the ability to identify any anti-virus installed on the infected system.

T1547.001
Registry Run Keys / Startup Folder
MalwareKasidet

Kasidet creates a Registry Run key to establish persistence.

T1686
Disable or Modify System Firewall
MalwareKasidet

Kasidet has the ability to change firewall settings to allow a plug-in to be downloaded.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.