TinyZBot

S0004

Malware.View on attack.mitre.org

About this malware

TinyZBot is a bot written in C# that was developed by Cleaver.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1056.001
Keylogging

TinyZBot contains keylogger functionality.

T1059.003
Windows Command Shell

TinyZBot supports execution from the command-line.

T1113
Screen Capture

TinyZBot contains screen capture functionality.

T1115
Clipboard Data

TinyZBot contains functionality to collect information from the clipboard.

T1543.003
Windows Service

TinyZBot can install as a Windows service for persistence.

T1547.001
Registry Run Keys / Startup Folder

TinyZBot can create a shortcut in the Windows startup folder for persistence.

T1547.009
Shortcut Modification

TinyZBot can create a shortcut in the Windows startup folder for persistence.

T1685
Disable or Modify Tools

TinyZBot can disable Avira anti-virus.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cylance Cleaver Open source
    Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.