Microsoft. (2016, June 9). Reverse-engineering DUBNIUM. Retrieved March 31, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
GroupDarkhotel | Darkhotel has used malware that is disguised as a Secure Shell (SSH) tool. |
| T1105 Ingress Tool Transfer |
GroupDarkhotel | Darkhotel has used first-stage payloads that download additional malware from C2 servers. |
| T1203 Exploitation for Client Execution |
GroupDarkhotel | Darkhotel has exploited Adobe Flash vulnerability CVE-2015-8651 for execution. |
| T1497.001 System Checks |
GroupDarkhotel | Darkhotel malware has used a series of checks to determine if it's being analyzed; checks include the length of executable names, if a filename ends with |
| T1518.001 Security Software Discovery |
GroupDarkhotel | Darkhotel has searched for anti-malware strings and anti-virus processes running on the system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.