EvilGrab

S0152

Malware.View on attack.mitre.org

About this malware

EvilGrab is a malware family with common reconnaissance capabilities. It has been deployed by menuPass via malicious Microsoft Office documents as part of spearphishing campaigns.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1056.001
Keylogging

EvilGrab has the capability to capture keystrokes.

T1113
Screen Capture

EvilGrab has the capability to capture screenshots.

T1123
Audio Capture

EvilGrab has the capability to capture audio from a victim machine.

T1125
Video Capture

EvilGrab has the capability to capture video from a victim machine.

T1547.001
Registry Run Keys / Startup Folder

EvilGrab adds a Registry Run key for ctfmon.exe to establish persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. PWC Cloud Hopper Technical Annex April 2017 Open source
    PwC and BAE Systems. (2017, April). Operation Cloud Hopper: Technical Annex. Retrieved April 13, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.