ATT&CKSoftwareDealersChoice

DealersChoice

S0243

Malware.View on attack.mitre.org

About this malware

DealersChoice is a Flash exploitation framework used by APT28.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1059.003
Windows Command Shell

DealersChoice makes modifications to open-source scripts from GitHub and executes them on the victim’s machine.

T1071.001
Web Protocols

DealersChoice uses HTTP for communication with the C2 server.

T1203
Exploitation for Client Execution

DealersChoice leverages vulnerable versions of Flash to perform execution.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Sofacy DealersChoice Open source
    Falcone, R. (2018, March 15). Sofacy Uses DealersChoice to Target European Government Agency. Retrieved June 4, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.