Malware.View on attack.mitre.org
Rover is malware suspected of being used for espionage purposes. It was used in 2015 in a targeted email sent to an Indian Ambassador to Afghanistan.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Rover searches for files on local drives based on a predefined list of file extensions. |
| T1020 Automated Exfiltration |
Rover automatically searches for files on local drives based on a predefined list of file extensions and sends them to the command and control server every 60 minutes. Rover also automatically sends keylogger files and screenshots to the C2 server on a regular timeframe. |
| T1025 Data from Removable Media |
Rover searches for files on attached removable drives based on a predefined list of file extensions every five seconds. |
| T1056.001 Keylogging |
Rover has keylogging functionality. |
| T1074.001 Local Data Staging |
Rover copies files from removable drives to |
| T1083 File and Directory Discovery |
Rover automatically searches for files on local drives based on a predefined list of file extensions. |
| T1112 Modify Registry |
Rover has functionality to remove Registry Run key persistence as a cleanup procedure. |
| T1113 Screen Capture |
Rover takes screenshots of the compromised system's desktop and saves them to |
| T1119 Automated Collection |
Rover automatically collects files from the local system and removable drives based on a predefined list of file extensions on a regular timeframe. |
| T1547.001 Registry Run Keys / Startup Folder |
Rover persists by creating a Registry entry in |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.