Malware.View on attack.mitre.org
Exaramel for Windows is a backdoor used for targeting Windows systems. The Linux version is tracked separately under Exaramel for Linux.
| Technique | Procedure example |
|---|---|
| T1027.011 Fileless Storage |
Exaramel for Windows stores the backdoor's configuration in the Registry in XML format. |
| T1036.004 Masquerade Task or Service |
The Exaramel for Windows dropper creates and starts a Windows service named wsmprovav with the description “Windows Check AV” in an apparent attempt to masquerade as a legitimate service. |
| T1059.003 Windows Command Shell |
Exaramel for Windows has a command to launch a remote shell and executes commands on the victim’s machine. |
| T1059.005 Visual Basic |
Exaramel for Windows has a command to execute VBS scripts on the victim’s machine. |
| T1074.001 Local Data Staging |
Exaramel for Windows specifies a path to store files scheduled for exfiltration. |
| T1112 Modify Registry |
Exaramel for Windows adds the configuration to the Registry in XML format. |
| T1543.003 Windows Service |
The Exaramel for Windows dropper creates and starts a Windows service named wsmprovav with the description “Windows Check AV.” |
| T1560 Archive Collected Data |
Exaramel for Windows automatically encrypts files before sending them to the C2 server. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.