Duncan, B., Harbison, M. (2019, January 23). Russian Language Malspam Pushing Redaman Banking Malware. Retrieved June 16, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareRTM | RTM strings, network data, configuration, and modules are encrypted with a modified RC4 algorithm. |
| T1027.015 Compression |
MalwareRTM | RTM has been delivered to targets as various archive files including ZIP, 7-ZIP, and RAR. |
| T1036 Masquerading |
MalwareRTM | RTM has been delivered as archived Windows executable files masquerading as PDF documents. |
| T1036.004 Masquerade Task or Service |
MalwareRTM | RTM has named the scheduled task it creates "Windows Update". |
| T1053.005 Scheduled Task |
MalwareRTM | RTM tries to add a scheduled task to establish persistence. |
| T1056.001 Keylogging |
MalwareRTM | RTM can record keystrokes from both the keyboard and virtual keyboard. |
| T1070.004 File Deletion |
MalwareRTM | RTM can delete all files created during its execution. |
| T1071.001 Web Protocols |
MalwareRTM | RTM has initiated connections to external domains using HTTPS. |
| T1083 File and Directory Discovery |
MalwareRTM | RTM can check for specific files and directories associated with virtualization and malware analysis. |
| T1102.001 Dead Drop Resolver |
MalwareRTM | RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. RTM has also hidden Pony C2 server IP addresses within transactions on the Bitcoin and Namecoin blockchain. |
| T1105 Ingress Tool Transfer |
MalwareRTM | RTM can download additional files. |
| T1113 Screen Capture |
MalwareRTM | RTM can capture screenshots. |
| T1115 Clipboard Data |
MalwareRTM | RTM collects data from the clipboard. |
| T1119 Automated Collection |
MalwareRTM | RTM monitors browsing activity and automatically captures screenshots if a victim browses to a URL matching one of a list of strings. |
| T1120 Peripheral Device Discovery |
MalwareRTM | RTM can obtain a list of smart card readers attached to the victim. |
| T1204.002 Malicious File |
MalwareRTM | RTM has relied on users opening malicious email attachments, decompressing the attached archive, and double-clicking the executable within. |
| T1218.011 Rundll32 |
MalwareRTM | RTM runs its core DLL file using rundll32.exe. |
| T1497 Virtualization/Sandbox Evasion |
MalwareRTM | RTM can detect if it is running within a sandbox or other virtualized analysis environment. |
| T1553.004 Install Root Certificate |
MalwareRTM | RTM can add a certificate to the Windows store. |
| T1566.001 Spearphishing Attachment |
MalwareRTM | RTM has been delivered via spearphishing attachments disguised as PDF documents. |
| T1568 Dynamic Resolution |
MalwareRTM | RTM has resolved Pony C2 server IP addresses by either converting Bitcoin blockchain transaction data to specific octets, or accessing IP addresses directly within the Namecoin blockchain. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.