Malware.View on attack.mitre.org
LiteDuke is a third stage backdoor that was used by APT29, primarily in 2014-2015. LiteDuke used the same dropper as PolyglotDuke, and was found on machines also compromised by MiniDuke.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
LiteDuke can query the Registry to check for the presence of |
| T1016 System Network Configuration Discovery |
LiteDuke has the ability to discover the proxy configuration of Firefox and/or Opera. |
| T1027.002 Software Packing |
LiteDuke has been packed with multiple layers of encryption. |
| T1027.003 Steganography |
LiteDuke has used image files to hide its loader component. |
| T1033 System Owner/User Discovery |
LiteDuke can enumerate the account name on a targeted system. |
| T1070.004 File Deletion |
LiteDuke can securely delete files by first writing random data to the file. |
| T1071.001 Web Protocols |
LiteDuke can use HTTP GET requests in C2 communications. |
| T1082 System Information Discovery |
LiteDuke can enumerate the CPUID and BIOS version on a compromised system. |
| T1105 Ingress Tool Transfer |
LiteDuke has the ability to download files. |
| T1140 Deobfuscate/Decode Files or Information |
LiteDuke has the ability to decrypt and decode multiple layers of obfuscation. |
| T1497.003 Time Based Checks |
LiteDuke can wait 30 seconds before executing additional code if security software is detected. |
| T1518.001 Security Software Discovery |
LiteDuke has the ability to check for the presence of Kaspersky security software. |
| T1547.001 Registry Run Keys / Startup Folder |
LiteDuke can create persistence by adding a shortcut in the |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.