Dyre

S0024

Malware.View on attack.mitre.org

About this malware

Dyre is a banking Trojan that has been used for financial gain.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1007
System Service Discovery

Dyre has the ability to identify running services on a compromised host.

T1016
System Network Configuration Discovery

Dyre has the ability to identify network settings on a compromised host.

T1027.002
Software Packing

Dyre has been delivered with encrypted resources and must be unpacked for execution.

T1033
System Owner/User Discovery

Dyre has the ability to identify the users on a compromised host.

T1041
Exfiltration Over C2 Channel

Dyre has the ability to send information staged on a compromised host externally to C2.

T1053.005
Scheduled Task

Dyre has the ability to achieve persistence by adding a new task in the task scheduler to run every minute.

T1055
Process Injection

Dyre has the ability to directly inject its code into the web browser process.

T1055.001
Dynamic-link Library Injection

Dyre injects into other processes to load modules.

T1071.001
Web Protocols

Dyre uses HTTPS for C2 communications.

T1074.001
Local Data Staging

Dyre has the ability to create files in a TEMP folder to act as a database to store information.

T1082
System Information Discovery

Dyre has the ability to identify the computer name, OS version, and hardware configuration on a compromised host.

T1105
Ingress Tool Transfer

Dyre has a command to download and executes additional files.

T1140
Deobfuscate/Decode Files or Information

Dyre decrypts resources needed for targeting the victim.

T1497.001
System Checks

Dyre can detect sandbox analysis environments by inspecting the process list and Registry.

T1518
Software Discovery

Dyre has the ability to identify installed programs on a compromised host.

View all 16 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Malwarebytes Dyreza November 2015 Open source
    hasherezade. (2015, November 4). A Technical Look At Dyreza. Retrieved June 15, 2020.
  2. Symantec Dyre June 2015 Open source
    Symantec Security Response. (2015, June 23). Dyre: Emerging threat on financial fraud landscape. Retrieved August 23, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.