ATT&CKReferencesKaspersky Flame

Kaspersky Flame

Gostev, A. (2012, May 28). The Flame: Questions and Answers. Retrieved March 1, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1036.010
Masquerade Account Name
MalwareFlame

Flame can create backdoor accounts with login `HelpAssistant` on domain connected systems if appropriate rights are available.

T1091
Replication Through Removable Media
MalwareFlame

Flame contains modules to infect USB sticks and spread laterally to other Windows systems the stick is plugged into using Autorun functionality.

T1113
Screen Capture
MalwareFlame

Flame can take regular screenshots when certain applications are open that are sent to the command and control server.

T1123
Audio Capture
MalwareFlame

Flame can record audio using any existing hardware recording devices.

T1136.001
Local Account
MalwareFlame

Flame can create backdoor accounts with login “HelpAssistant” on domain connected systems if appropriate rights are available.

T1210
Exploitation of Remote Services
MalwareFlame

Flame can use MS10-061 to exploit a print spooler vulnerability in a remote system with a shared printer in order to move laterally.

T1518.001
Security Software Discovery
MalwareFlame

Flame identifies security software such as antivirus through the Security module.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.