Su, V. et al. (2019, December 11). Waterbear Returns, Uses API Hooking to Evade Security. Retrieved February 22, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareWaterbear | Waterbear can query the Registry key |
| T1027.005 Indicator Removal from Tools |
MalwareWaterbear | Waterbear can scramble functions not to be executed again with random values. |
| T1027.013 Encrypted/Encoded File |
MalwareWaterbear | Waterbear has used RC4 encrypted shellcode and encrypted functions. |
| T1049 System Network Connections Discovery |
MalwareWaterbear | Waterbear can use API hooks on `GetExtendedTcpTable` to retrieve a table containing a list of TCP endpoints available to the application. |
| T1055 Process Injection |
MalwareWaterbear | Waterbear can inject decrypted shellcode into the LanmanServer service. |
| T1055.003 Thread Execution Hijacking |
MalwareWaterbear | Waterbear can use thread injection to inject shellcode into the process of security software. |
| T1057 Process Discovery |
MalwareWaterbear | Waterbear can identify the process for a specific security product. |
| T1105 Ingress Tool Transfer |
MalwareWaterbear | Waterbear can receive and load executables from remote C2 servers. |
| T1106 Native API |
MalwareWaterbear | Waterbear can leverage API functions for execution. |
| T1112 Modify Registry |
MalwareWaterbear | Waterbear has deleted certain values from the Registry to load a malicious DLL. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWaterbear | Waterbear has the ability to decrypt its RC4 encrypted payload for execution. |
| T1518.001 Security Software Discovery |
MalwareWaterbear | Waterbear can find the presence of a specific security software. |
| T1574.001 DLL |
GroupBlackTech | BlackTech has used DLL side loading by giving DLLs hardcoded names and placing them in searched directories. |
| T1574.001 DLL |
MalwareWaterbear | Waterbear has used DLL side loading to import and load a malicious DLL loader. |
| T1685 Disable or Modify Tools |
MalwareWaterbear | Waterbear can hook the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.