Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
KGH_SPY can send a file containing victim system information to C2. |
| T1027.013 Encrypted/Encoded File |
KGH_SPY has used encrypted strings in its installer. |
| T1036.005 Match Legitimate Resource Name or Location |
KGH_SPY has masqueraded as a legitimate Windows tool. |
| T1037.001 Logon Script (Windows) |
KGH_SPY has the ability to set the |
| T1041 Exfiltration Over C2 Channel |
KGH_SPY can exfiltrate collected information from the host to the C2 server. |
| T1056.001 Keylogging |
KGH_SPY can perform keylogging by polling the |
| T1059.001 PowerShell |
KGH_SPY can execute PowerShell commands on the victim's machine. |
| T1059.003 Windows Command Shell |
KGH_SPY has the ability to set a Registry key to run a cmd.exe command. |
| T1071.001 Web Protocols |
KGH_SPY can send data to C2 with HTTP POST requests. |
| T1074.001 Local Data Staging |
KGH_SPY can save collected system information to a file named "info" before exfiltration. |
| T1083 File and Directory Discovery |
KGH_SPY can enumerate files and directories on a compromised host. |
| T1105 Ingress Tool Transfer |
KGH_SPY has the ability to download and execute code from remote servers. |
| T1114.001 Local Email Collection |
KGH_SPY can harvest data from mail clients. |
| T1140 Deobfuscate/Decode Files or Information |
KGH_SPY can decrypt encrypted strings and write them to a newly created folder. |
| T1204.002 Malicious File |
KGH_SPY has been spread through Word documents containing malicious macros. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.