Boutin, J. (2020, October 12). ESET takes part in global operation to disrupt Trickbot. Retrieved March 15, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareTrickBot | TrickBot uses module networkDll for process list discovery. |
| T1110.004 Credential Stuffing |
MalwareTrickBot | TrickBot uses brute-force attack against RDP with rdpscanDll module. |
| T1135 Network Share Discovery |
MalwareTrickBot | TrickBot module shareDll/mshareDll discovers network shares via the WNetOpenEnumA API. |
| T1210 Exploitation of Remote Services |
MalwareTrickBot | TrickBot utilizes EternalBlue and EternalRomance exploits for lateral movement in the modules wormwinDll, wormDll, mwormDll, nwormDll, tabDll. |
| T1219 Remote Access Tools |
MalwareTrickBot | TrickBot uses vncDll module to remote control the victim machine. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTrickBot | TrickBot establishes persistence in the Startup folder. |
| T1559.001 Component Object Model |
MalwareTrickBot | TrickBot used COM to setup scheduled task for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.