Huss, D., et al. (2017, February 2). Oops, they did it again: APT Targets Russia and Belarus with ZeroT and PlugX. Retrieved April 5, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.002 Steganography |
MalwareZeroT | ZeroT has retrieved stage 2 payloads as Bitmap images that use Least Significant Bit (LSB) steganography. |
| T1016 System Network Configuration Discovery |
MalwareZeroT | ZeroT gathers the victim's IP address and domain information, and then sends it to its C2 server. |
| T1027.002 Software Packing |
MalwareZeroT | Some ZeroT DLL files have been packed with UPX. |
| T1027.013 Encrypted/Encoded File |
MalwareZeroT | ZeroT has encrypted its payload with RC4. |
| T1027.016 Junk Code Insertion |
MalwareZeroT | ZeroT has obfuscated DLLs and functions using dummy API calls inserted between real instructions. |
| T1071.001 Web Protocols |
MalwareZeroT | ZeroT has used HTTP for C2. |
| T1082 System Information Discovery |
MalwareZeroT | ZeroT gathers the victim's computer name, Windows version, and system language, and then sends it to its C2 server. |
| T1105 Ingress Tool Transfer |
MalwareZeroT | ZeroT can download additional payloads onto the victim. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareZeroT | ZeroT shellcode decrypts and decompresses its RC4-encrypted payload. |
| T1543.003 Windows Service |
MalwarePlugX | PlugX can be added as a service to establish persistence. PlugX also has a module to change service configurations as well as start, control, and delete services. |
| T1543.003 Windows Service |
MalwareZeroT | ZeroT can add a new service to ensure PlugX persists on the system when delivered as another payload onto the system. |
| T1548.002 Bypass User Account Control |
MalwareZeroT | Many ZeroT samples can perform UAC bypass by using eventvwr.exe to execute a malicious file. |
| T1573.001 Symmetric Cryptography |
MalwareZeroT | ZeroT has used RC4 to encrypt C2 traffic. |
| T1574.001 DLL |
MalwareZeroT | ZeroT has used DLL side-loading to load malicious payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.