Malware.View on attack.mitre.org
Emissary is a Trojan that has been used by Lotus Blossom. It shares code with Elise, with both Trojans being part of a malware group referred to as LStudio.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
Emissary has the capability to execute the command |
| T1016 System Network Configuration Discovery |
Emissary has the capability to execute the command |
| T1027.001 Binary Padding |
A variant of Emissary appends junk data to the end of its DLL file to create a large file that may exceed the maximum size that anti-virus programs can scan. |
| T1027.013 Encrypted/Encoded File |
Variants of Emissary encrypt payloads using various XOR ciphers, as well as a custom algorithm that uses the "srand" and "rand" functions. |
| T1055.001 Dynamic-link Library Injection |
Emissary injects its DLL file into a newly spawned Internet Explorer process. |
| T1059.003 Windows Command Shell |
Emissary has the capability to create a remote shell and execute specified commands. |
| T1069.001 Local Groups |
Emissary has the capability to execute the command |
| T1071.001 Web Protocols |
Emissary uses HTTP or HTTPS for C2. |
| T1082 System Information Discovery |
Emissary has the capability to execute ver and systeminfo commands. |
| T1105 Ingress Tool Transfer |
Emissary has the capability to download files from the C2 server. |
| T1218.011 Rundll32 |
Variants of Emissary have used rundll32.exe in Registry values added to establish persistence. |
| T1543.003 Windows Service |
Emissary is capable of configuring itself as a service. |
| T1547.001 Registry Run Keys / Startup Folder |
Variants of Emissary have added Run Registry keys to establish persistence. |
| T1573.001 Symmetric Cryptography |
The C2 server response to a beacon sent by a variant of Emissary contains a 36-character GUID value that is used as an encryption key for subsequent network communications. Some variants of Emissary use various XOR operations to encrypt C2 data. |
| T1615 Group Policy Discovery |
Emissary has the capability to execute |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.