Malware.View on attack.mitre.org
GreyEnergy is a backdoor written in C and compiled in Visual Studio. GreyEnergy shares similarities with the BlackEnergy malware and is thought to be the successor of it.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
GreyEnergy has a module for Mimikatz to collect Windows credentials from the victim’s machine. |
| T1007 System Service Discovery |
GreyEnergy enumerates all Windows services. |
| T1027.002 Software Packing |
GreyEnergy is packed for obfuscation. |
| T1027.013 Encrypted/Encoded File |
GreyEnergy encrypts its configuration files with AES-256 and also encrypts its strings. |
| T1055.002 Portable Executable Injection |
GreyEnergy has a module to inject a PE binary into a remote process. |
| T1056.001 Keylogging |
GreyEnergy has a module to harvest pressed keystrokes. |
| T1059.003 Windows Command Shell |
GreyEnergy uses cmd.exe to execute itself in-memory. |
| T1070.004 File Deletion |
GreyEnergy can securely delete a file by hooking into the DeleteFileA and DeleteFileW functions in the Windows API. |
| T1071.001 Web Protocols |
GreyEnergy uses HTTP and HTTPS for C2 communications. |
| T1090.003 Multi-hop Proxy |
GreyEnergy has used Tor relays for Command and Control servers. |
| T1105 Ingress Tool Transfer |
GreyEnergy can download additional modules and payloads. |
| T1112 Modify Registry |
GreyEnergy modifies conditions in the Registry and adds keys. |
| T1218.011 Rundll32 |
GreyEnergy uses PsExec locally in order to execute rundll32.exe at the highest privileges (NTAUTHORITY\SYSTEM). |
| T1543.003 Windows Service |
GreyEnergy chooses a service, drops a DLL file, and writes it to that serviceDLL Registry key. |
| T1553.002 Code Signing |
GreyEnergy digitally signs the malware with a code-signing certificate. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.