ATT&CKReferencesThreatpost Lizar May 2021

Threatpost Lizar May 2021

Seals, T. (2021, May 14). FIN7 Backdoor Masquerades as Ethical Hacking Tool. Retrieved February 2, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareLizar

Lizar can run Mimikatz to harvest credentials.

T1057
Process Discovery
MalwareLizar

Lizar has a plugin designed to obtain a list of processes.

T1059.003
Windows Command Shell
MalwareLizar

Lizar has a command to open the command-line on the infected system.

T1113
Screen Capture
MalwareLizar

Lizar can take JPEG screenshots of an infected system. Lizar has also used a plugin to take a screenshot of the infected system.

T1217
Browser Information Discovery
MalwareLizar

Lizar can retrieve browser history and database files.

T1573
Encrypted Channel
MalwareLizar

Lizar can support encrypted communications between the client and server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.