HIDEDRV

S0135

Malware.View on attack.mitre.org

About this malware

HIDEDRV is a rootkit used by APT28. It has been deployed along with Downdelph to execute and hide that malware.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1014
Rootkit

HIDEDRV is a rootkit that hides certain operating system artifacts.

T1055.001
Dynamic-link Library Injection

HIDEDRV injects a DLL for Downdelph into the explorer.exe process.

Groups that use it1

Campaigns0

None recorded.

References2

  1. ESET Sednit Part 3 Open source
    ESET. (2016, October). En Route with Sednit - Part 3: A Mysterious Downloader. Retrieved November 21, 2016.
  2. Sekoia HideDRV Oct 2016 Open source
    Rascagnères, P.. (2016, October 27). Rootkit analysis: Use case on HideDRV. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.