MCMD

S0500

Tool.View on attack.mitre.org

About this tool

MCMD is a remote access tool that provides remote command shell capability used by Dragonfly.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1005
Data from Local System

MCMD has the ability to upload files from an infected device.

T1027
Obfuscated Files or Information

MCMD can Base64 encode output strings prior to sending to C2.

T1036.005
Match Legitimate Resource Name or Location

MCMD has been named Readme.txt to appear legitimate.

T1053.005
Scheduled Task

MCMD can use scheduled tasks for persistence.

T1059.003
Windows Command Shell

MCMD can launch a console process (cmd.exe) with redirected standard input and output.

T1070.009
Clear Persistence

MCMD has the ability to remove set Registry Keys, including those used for persistence.

T1071.001
Web Protocols

MCMD can use HTTPS in communication with C2 web servers.

T1105
Ingress Tool Transfer

MCMD can upload additional files to a compromised host.

T1547.001
Registry Run Keys / Startup Folder

MCMD can use Registry Run Keys for persistence.

T1564.003
Hidden Window

MCMD can modify processes to prevent them from being visible on the desktop.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Secureworks MCMD July 2019 Open source
    Secureworks. (2019, July 24). MCMD Malware Analysis. Retrieved August 13, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.