Malware.View on attack.mitre.org
PipeMon is a multi-stage modular backdoor used by Winnti Group.
| Technique | Procedure example |
|---|---|
| T1008 Fallback Channels |
PipeMon can switch to an alternate C2 domain when a particular date has been reached. |
| T1016 System Network Configuration Discovery |
PipeMon can collect and send the local IP address, RDP information, and the network adapter physical address as a part of its C2 beacon. |
| T1027.011 Fileless Storage |
PipeMon has stored its encrypted payload in the Registry under `HKLM\SOFTWARE\Microsoft\Print\Components\`. |
| T1027.013 Encrypted/Encoded File |
PipeMon modules are stored encrypted on disk. |
| T1036.005 Match Legitimate Resource Name or Location |
PipeMon modules are stored on disk with seemingly benign names including use of a file extension associated with a popular word processor. |
| T1055.001 Dynamic-link Library Injection |
PipeMon can inject its modules into various processes using reflective DLL loading. |
| T1057 Process Discovery |
PipeMon can iterate over the running processes to find a suitable injection target. |
| T1082 System Information Discovery |
PipeMon can collect and send OS version and computer name as a part of its C2 beacon. |
| T1095 Non-Application Layer Protocol |
The PipeMon communication module can use a custom protocol based on TLS over TCP. |
| T1105 Ingress Tool Transfer |
PipeMon can install additional modules via C2 commands. |
| T1106 Native API |
PipeMon's first stage has been executed by a call to |
| T1112 Modify Registry |
PipeMon has modified the Registry to store its encrypted payload. |
| T1124 System Time Discovery |
PipeMon can send time zone information from a compromised host to C2. |
| T1129 Shared Modules |
PipeMon has used call to |
| T1134.002 Create Process with Token |
PipeMon can attempt to gain administrative privileges using token impersonation. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.