Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
Sykipot may use |
| T1016 System Network Configuration Discovery |
Sykipot may use |
| T1018 Remote System Discovery |
Sykipot may use |
| T1049 System Network Connections Discovery |
Sykipot may use |
| T1055.001 Dynamic-link Library Injection |
Sykipot injects itself into running instances of outlook.exe, iexplore.exe, or firefox.exe. |
| T1056.001 Keylogging |
Sykipot contains keylogging functionality to steal passwords. |
| T1057 Process Discovery |
Sykipot may gather a list of running processes by running |
| T1087.002 Domain Account |
Sykipot may use |
| T1111 Multi-Factor Authentication Interception |
Sykipot is known to contain functionality that enables targeting of smart card technologies to proxy authentication for connections to restricted network resources using detected hardware tokens. |
| T1547.001 Registry Run Keys / Startup Folder |
Sykipot has been known to establish persistence by adding programs to the Run Registry key. |
| T1573.002 Asymmetric Cryptography |
Sykipot uses SSL for encrypting C2 communications. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.