Hikit

S0009

Malware.View on attack.mitre.org

About this malware

Hikit is malware that has been used by Axiom for late-stage persistence and exfiltration after the initial compromise.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1005
Data from Local System

Hikit can upload files from compromised machines.

T1014
Rootkit

Hikit is a Rootkit that has been used by Axiom.

T1059.003
Windows Command Shell

Hikit has the ability to create a remote shell and run given commands.

T1071.001
Web Protocols

Hikit has used HTTP for C2.

T1090.001
Internal Proxy

Hikit supports peer connections.

T1105
Ingress Tool Transfer

Hikit has the ability to download files to a compromised host.

T1553.004
Install Root Certificate

Hikit installs a self-generated certificate to the local trust store as a root CA and Trusted Publisher.

T1553.006
Code Signing Policy Modification

Hikit has attempted to disable driver signing verification by tampering with several Registry keys prior to the loading of a rootkit driver component.

T1566
Phishing

Hikit has been spread through spear phishing.

T1573.001
Symmetric Cryptography

Hikit performs XOR encryption.

T1574.001
DLL

Hikit has used DLL to load oci.dll as a persistence mechanism.

Groups that use it1

Campaigns0

None recorded.

References2

  1. FireEye Hikit Rootkit Open source
    Glyer, C., Kazanciyan, R. (2012, August 20). The “Hikit” Rootkit: Advanced and Persistent Attack Techniques (Part 1). Retrieved November 17, 2024.
  2. Novetta-Axiom Open source
    Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.