Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
When it first starts, BADNEWS crawls the victim's local drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt. |
| T1025 Data from Removable Media |
BADNEWS copies files with certain extensions from USB devices to |
| T1036.001 Invalid Code Signature |
BADNEWS is sometimes signed with an invalid Authenticode certificate in an apparent effort to make it look more legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
BADNEWS attempts to hide its payloads using legitimate filenames. |
| T1039 Data from Network Shared Drive |
When it first starts, BADNEWS crawls the victim's mapped drives and collects documents with the following extensions: .doc, .docx, .pdf, .ppt, .pptx, and .txt. |
| T1053.005 Scheduled Task |
BADNEWS creates a scheduled task to establish by executing a malicious payload every subsequent minute. |
| T1055.012 Process Hollowing |
BADNEWS has a command to download an .exe and use process hollowing to inject it into a new process. |
| T1056.001 Keylogging |
When it first starts, BADNEWS spawns a new thread to log keystrokes. |
| T1059.003 Windows Command Shell |
BADNEWS is capable of executing commands via cmd.exe. |
| T1071.001 Web Protocols |
BADNEWS establishes a backdoor over HTTP. |
| T1074.001 Local Data Staging |
BADNEWS copies documents under 15MB found on the victim system to is the user's |
| T1083 File and Directory Discovery |
BADNEWS identifies files with certain extensions from USB devices, then copies them to a predefined directory. |
| T1102.001 Dead Drop Resolver |
BADNEWS collects C2 information via a dead drop resolver. |
| T1102.002 Bidirectional Communication |
BADNEWS can use multiple C2 channels, including RSS feeds, Github, forums, and blogs. |
| T1105 Ingress Tool Transfer |
BADNEWS is capable of downloading additional files through C2 channels, including a new version of itself. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.