ATT&CKReferencesEmissary Trojan Feb 2016

Emissary Trojan Feb 2016

Falcone, R. and Miller-Osborn, J. (2016, February 3). Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve?. Retrieved February 15, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareEmissary

Emissary has the capability to execute the command net start to interact with services.

T1016
System Network Configuration Discovery
MalwareEmissary

Emissary has the capability to execute the command ipconfig /all.

T1027.001
Binary Padding
MalwareEmissary

A variant of Emissary appends junk data to the end of its DLL file to create a large file that may exceed the maximum size that anti-virus programs can scan.

T1027.013
Encrypted/Encoded File
MalwareEmissary

Variants of Emissary encrypt payloads using various XOR ciphers, as well as a custom algorithm that uses the "srand" and "rand" functions.

T1069.001
Local Groups
MalwareEmissary

Emissary has the capability to execute the command net localgroup administrators.

T1082
System Information Discovery
MalwareEmissary

Emissary has the capability to execute ver and systeminfo commands.

T1218.011
Rundll32
MalwareEmissary

Variants of Emissary have used rundll32.exe in Registry values added to establish persistence.

T1543.003
Windows Service
MalwareEmissary

Emissary is capable of configuring itself as a service.

T1547.001
Registry Run Keys / Startup Folder
MalwareEmissary

Variants of Emissary have added Run Registry keys to establish persistence.

T1615
Group Policy Discovery
MalwareEmissary

Emissary has the capability to execute gpresult.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.