Malware.View on attack.mitre.org
build_downer is a downloader that has been used by BRONZE BUTLER since at least 2019.
| Technique | Procedure example |
|---|---|
| T1027.003 Steganography |
build_downer can extract malware from a downloaded JPEG. |
| T1036.004 Masquerade Task or Service |
build_downer has added itself to the Registry Run key as "NVIDIA" to appear legitimate. |
| T1105 Ingress Tool Transfer |
build_downer has the ability to download files from C2 to the infected host. |
| T1106 Native API |
build_downer has the ability to use the |
| T1124 System Time Discovery |
build_downer has the ability to determine the local time to ensure malware installation only happens during the hours that the infected system is active. |
| T1518.001 Security Software Discovery |
build_downer has the ability to detect if the infected host is running an anti-virus process. |
| T1547.001 Registry Run Keys / Startup Folder |
build_downer has the ability to add itself to the Registry Run key for persistence. |
| T1680 Local Storage Discovery |
build_downer has the ability to send system volume information to C2. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.