ATT&CKReferencesEFF Manul Aug 2016

EFF Manul Aug 2016

Galperin, E., Et al.. (2016, August). I Got a Letter From the Government the Other Day.... Retrieved April 25, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1055.012
Process Hollowing
MalwareBandook

Bandook has been launched by starting iexplore.exe and replacing it with Bandook's payload.

T1059.003
Windows Command Shell
MalwareBandook

Bandook is capable of spawning a Windows command shell.

T1120
Peripheral Device Discovery
MalwareBandook

Bandook can detect USB devices.

T1123
Audio Capture
MalwareBandook

Bandook has modules that are capable of capturing audio.

T1125
Video Capture
MalwareBandook

Bandook has modules that are capable of capturing video from a victim's webcam.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.