Arunpreet Singh, Clemens Kolbitsch. (2015, November 5). Defeating Darkhotel Just-In-Time Decryption. Retrieved April 15, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1124 System Time Discovery |
GroupDarkhotel | Darkhotel malware can obtain system time from a compromised host. |
| T1497 Virtualization/Sandbox Evasion |
GroupDarkhotel | Darkhotel malware has employed just-in-time decryption of strings to evade sandbox detection. |
| T1497.001 System Checks |
GroupDarkhotel | Darkhotel malware has used a series of checks to determine if it's being analyzed; checks include the length of executable names, if a filename ends with |
| T1497.002 User Activity Based Checks |
GroupDarkhotel | Darkhotel has used malware that repeatedly checks the mouse cursor position to determine if a real user is on the system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.