WinMM

S0059

Malware.View on attack.mitre.org

About this malware

WinMM is a full-featured, simple backdoor used by Naikon.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1008
Fallback Channels

WinMM is usually configured with primary and backup domains for C2 communications.

T1033
System Owner/User Discovery

WinMM uses NetUser-GetInfo to identify that it is running under an “Admin” account on the local system.

T1057
Process Discovery

WinMM sets a WH_CBT Windows hook to collect information on process creation.

T1071.001
Web Protocols

WinMM uses HTTP for C2.

T1082
System Information Discovery

WinMM collects the system name, OS version including service pack, and system install date and sends the information to the C2 server.

T1083
File and Directory Discovery

WinMM sets a WH_CBT Windows hook to search for and capture files on the victim.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Baumgartner Naikon 2015 Open source
    Baumgartner, K., Golovkin, M.. (2015, May). The MsnMM Campaigns: The Earliest Naikon APT Campaigns. Retrieved April 10, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.