PoisonIvy

S0012

Malware.View on attack.mitre.org

About this malware

PoisonIvy is a popular remote access tool (RAT) that has been used by many groups.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

PoisonIvy creates a backdoor through which remote attackers can steal system information.

T1010
Application Window Discovery

PoisonIvy captures window titles.

T1014
Rootkit

PoisonIvy starts a rootkit from a malicious file dropped to disk.

T1027
Obfuscated Files or Information

PoisonIvy hides any strings related to its own indicators of compromise.

T1055.001
Dynamic-link Library Injection

PoisonIvy can inject a malicious DLL into a process.

T1056.001
Keylogging

PoisonIvy contains a keylogger.

T1059.003
Windows Command Shell

PoisonIvy creates a backdoor through which remote attackers can open a command-line interface.

T1074.001
Local Data Staging

PoisonIvy stages collected data in a text file.

T1105
Ingress Tool Transfer

PoisonIvy creates a backdoor through which remote attackers can upload files.

T1112
Modify Registry

PoisonIvy creates a Registry subkey that registers a new system device.

T1480.002
Mutual Exclusion

PoisonIvy creates a mutex using either a custom or default value.

T1543.003
Windows Service

PoisonIvy creates a Registry subkey that registers a new service. PoisonIvy also creates a Registry entry modifying the Logical Disk Manager service to point to a malicious DLL dropped to disk.

T1547.001
Registry Run Keys / Startup Folder

PoisonIvy creates run key Registry entries pointing to a malicious executable dropped to disk.

T1547.014
Active Setup

PoisonIvy creates a Registry key in the Active Setup pointing to a malicious executable.

T1573.001
Symmetric Cryptography

PoisonIvy uses the Camellia cipher to encrypt communications.

Groups that use it14

Campaigns1

References3

  1. FireEye Poison Ivy Open source
    FireEye. (2014). POISON IVY: Assessing Damage and Extracting Intelligence. Retrieved September 19, 2024.
  2. Symantec Darkmoon Aug 2005 Open source
    Hayashi, K. (2005, August 18). Backdoor.Darkmoon. Retrieved February 23, 2018.
  3. Symantec Elderwood Sept 2012 Open source
    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.