Malware.View on attack.mitre.org
Rifdoor is a remote access trojan (RAT) that shares numerous code similarities with HotCroissant.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Rifdoor has the ability to identify the IP address of the compromised host. |
| T1027.001 Binary Padding |
Rifdoor has added four additional bytes of data upon launching, then saved the changed version as |
| T1027.013 Encrypted/Encoded File |
Rifdoor has encrypted strings with a single byte XOR algorithm. |
| T1033 System Owner/User Discovery |
Rifdoor has the ability to identify the username on the compromised host. |
| T1082 System Information Discovery |
Rifdoor has the ability to identify the Windows version on the compromised host. |
| T1204.002 Malicious File |
Rifdoor has been executed from malicious Excel or Word documents containing macros. |
| T1547.001 Registry Run Keys / Startup Folder |
Rifdoor has created a new registry entry at |
| T1566.001 Spearphishing Attachment |
Rifdoor has been distributed in e-mails with malicious Excel or Word documents. |
| T1573.001 Symmetric Cryptography |
Rifdoor has encrypted command and control (C2) communications with a stream cipher. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.