Lim, M.. (2019, April 26). BabyShark Malware Part Two – Attacks Continue Using KimJongRAT and PCRat . Retrieved October 7, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwareBabyShark | BabyShark has a PowerShell-based remote administration ability that can implement a PowerShell or C# based keylogger. |
| T1070.004 File Deletion |
MalwareBabyShark | BabyShark has cleaned up all files associated with the secondary payload execution. |
| T1105 Ingress Tool Transfer |
MalwareBabyShark | BabyShark has downloaded additional files from the C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.