Malware.View on attack.mitre.org
PoisonIvy is a popular remote access tool (RAT) that has been used by many groups.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
PoisonIvy creates a backdoor through which remote attackers can steal system information. |
| T1010 Application Window Discovery |
PoisonIvy captures window titles. |
| T1014 Rootkit |
PoisonIvy starts a rootkit from a malicious file dropped to disk. |
| T1027 Obfuscated Files or Information |
PoisonIvy hides any strings related to its own indicators of compromise. |
| T1055.001 Dynamic-link Library Injection |
PoisonIvy can inject a malicious DLL into a process. |
| T1056.001 Keylogging |
PoisonIvy contains a keylogger. |
| T1059.003 Windows Command Shell |
PoisonIvy creates a backdoor through which remote attackers can open a command-line interface. |
| T1074.001 Local Data Staging |
PoisonIvy stages collected data in a text file. |
| T1105 Ingress Tool Transfer |
PoisonIvy creates a backdoor through which remote attackers can upload files. |
| T1112 Modify Registry |
PoisonIvy creates a Registry subkey that registers a new system device. |
| T1480.002 Mutual Exclusion |
PoisonIvy creates a mutex using either a custom or default value. |
| T1543.003 Windows Service |
PoisonIvy creates a Registry subkey that registers a new service. PoisonIvy also creates a Registry entry modifying the Logical Disk Manager service to point to a malicious DLL dropped to disk. |
| T1547.001 Registry Run Keys / Startup Folder |
PoisonIvy creates run key Registry entries pointing to a malicious executable dropped to disk. |
| T1547.014 Active Setup |
PoisonIvy creates a Registry key in the Active Setup pointing to a malicious executable. |
| T1573.001 Symmetric Cryptography |
PoisonIvy uses the Camellia cipher to encrypt communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.