Malware.View on attack.mitre.org
Flame is a sophisticated toolkit that has been used to collect information since at least 2010, largely targeting Middle East countries.
| Technique | Procedure example |
|---|---|
| T1011.001 Exfiltration Over Bluetooth |
Flame has a module named BeetleJuice that contains Bluetooth functionality that may be used in different ways, including transmitting encoded information from the infected system over the Bluetooth protocol, acting as a Bluetooth beacon, and identifying other Bluetooth devices in the vicinity. |
| T1036.010 Masquerade Account Name |
Flame can create backdoor accounts with login `HelpAssistant` on domain connected systems if appropriate rights are available. |
| T1091 Replication Through Removable Media |
Flame contains modules to infect USB sticks and spread laterally to other Windows systems the stick is plugged into using Autorun functionality. |
| T1113 Screen Capture |
Flame can take regular screenshots when certain applications are open that are sent to the command and control server. |
| T1123 Audio Capture |
Flame can record audio using any existing hardware recording devices. |
| T1136.001 Local Account |
Flame can create backdoor accounts with login “HelpAssistant” on domain connected systems if appropriate rights are available. |
| T1210 Exploitation of Remote Services |
Flame can use MS10-061 to exploit a print spooler vulnerability in a remote system with a shared printer in order to move laterally. |
| T1218.011 Rundll32 |
Rundll32.exe is used as a way of executing Flame at the command-line. |
| T1518.001 Security Software Discovery |
Flame identifies security software such as antivirus through the Security module. |
| T1547.002 Authentication Package |
Flame can use Windows Authentication Packages for persistence. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.