Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1021.002 SMB/Windows Admin Shares |
The Regin malware platform can use Windows admin shares to move laterally. |
| T1036.001 Invalid Code Signature |
Regin stage 1 modules for 64-bit systems have been found to be signed with fake certificates masquerading as originating from Microsoft Corporation and Broadcom Corporation. |
| T1040 Network Sniffing |
Regin appears to have functionality to sniff for credentials passed over HTTP, SMTP, and SMB. |
| T1056.001 Keylogging |
Regin contains a keylogger. |
| T1071.001 Web Protocols |
The Regin malware platform supports many standard protocols, including HTTP and HTTPS. |
| T1071.002 File Transfer Protocols |
The Regin malware platform supports many standard protocols, including SMB. |
| T1090.002 External Proxy |
Regin leveraged several compromised universities as proxies to obscure its origin. |
| T1095 Non-Application Layer Protocol |
The Regin malware platform can use ICMP to communicate between infected computers. |
| T1112 Modify Registry |
Regin appears to have functionality to modify remote Registry information. |
| T1564.004 NTFS File Attributes |
The Regin malware platform uses Extended Attributes to store encrypted executables. |
| T1564.005 Hidden File System |
Regin has used a hidden file system to store some of its components. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.