Malware.View on attack.mitre.org
Revenge RAT is a freely available remote access tool written in .NET (C#).
| Technique | Procedure example |
|---|---|
| T1003 OS Credential Dumping |
Revenge RAT has a plugin for credential harvesting. |
| T1016 System Network Configuration Discovery |
Revenge RAT collects the IP address and MAC address from the system. |
| T1021.001 Remote Desktop Protocol |
Revenge RAT has a plugin to perform RDP access. |
| T1033 System Owner/User Discovery |
Revenge RAT gathers the username from the system. |
| T1053.005 Scheduled Task |
Revenge RAT schedules tasks to run malicious scripts at different intervals. |
| T1056.001 Keylogging |
Revenge RAT has a plugin for keylogging. |
| T1059.001 PowerShell |
Revenge RAT uses the PowerShell command |
| T1059.003 Windows Command Shell |
Revenge RAT uses cmd.exe to execute commands and run scripts on the victim's machine. |
| T1082 System Information Discovery |
Revenge RAT collects the CPU information, OS information, and system language. |
| T1102.002 Bidirectional Communication |
Revenge RAT used blogpost.com as its primary command and control server during a campaign. |
| T1105 Ingress Tool Transfer |
Revenge RAT has the ability to upload and download files. |
| T1113 Screen Capture |
Revenge RAT has a plugin for screen capture. |
| T1123 Audio Capture |
Revenge RAT has a plugin for microphone interception. |
| T1125 Video Capture |
Revenge RAT has the ability to access the webcam. |
| T1132.001 Standard Encoding |
Revenge RAT uses Base64 to encode information sent to the C2 server. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.