Malware.View on attack.mitre.org
HARDRAIN is a Trojan malware variant reportedly used by the North Korean government.
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
HARDRAIN uses FakeTLS to communicate with its C2 server. |
| T1059.003 Windows Command Shell |
HARDRAIN uses cmd.exe to execute |
| T1090 Proxy |
HARDRAIN uses the command |
| T1571 Non-Standard Port |
HARDRAIN binds and listens on port 443 with a FakeTLS method. |
| T1686.003 Windows Host Firewall |
HARDRAIN opens the Windows Firewall to modify incoming connections. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.