Malware.View on attack.mitre.org
NETWIRE is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012.
| Technique | Procedure example |
|---|---|
| T1010 Application Window Discovery |
NETWIRE can discover and close windows on controlled systems. |
| T1016 System Network Configuration Discovery |
NETWIRE can collect the IP address of a compromised host. |
| T1027 Obfuscated Files or Information |
NETWIRE has used a custom obfuscation algorithm to hide strings including Registry keys, APIs, and DLL names. |
| T1027.002 Software Packing |
NETWIRE has used .NET packer tools to evade detection. |
| T1027.011 Fileless Storage |
NETWIRE can store its configuration information in the Registry under `HKCU:\Software\Netwire`. |
| T1036.001 Invalid Code Signature |
The NETWIRE client has been signed by fake and invalid digital certificates. |
| T1036.005 Match Legitimate Resource Name or Location |
NETWIRE has masqueraded as legitimate software including TeamViewer and macOS Finder. |
| T1049 System Network Connections Discovery |
NETWIRE can capture session logon details from a compromised host. |
| T1053.003 Cron |
NETWIRE can use crontabs to establish persistence. |
| T1053.005 Scheduled Task |
NETWIRE can create a scheduled task to establish persistence. |
| T1055 Process Injection |
NETWIRE can inject code into system processes including notepad.exe, svchost.exe, and vbc.exe. |
| T1055.012 Process Hollowing |
The NETWIRE payload has been injected into benign Microsoft executables via process hollowing. |
| T1056.001 Keylogging |
NETWIRE can perform keylogging. |
| T1057 Process Discovery |
NETWIRE can discover processes on compromised hosts. |
| T1059.001 PowerShell |
The NETWIRE binary has been executed via PowerShell script. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.