Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Crutch can exfiltrate files from compromised systems. |
| T1008 Fallback Channels |
Crutch has used a hardcoded GitHub repository as a fallback channel. |
| T1020 Automated Exfiltration |
Crutch has automatically exfiltrated stolen files to Dropbox. |
| T1025 Data from Removable Media |
Crutch can monitor removable drives and exfiltrate files matching a given extension list. |
| T1036.004 Masquerade Task or Service |
Crutch has established persistence with a scheduled task impersonating the Outlook item finder. |
| T1041 Exfiltration Over C2 Channel |
Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API). |
| T1053.005 Scheduled Task |
Crutch has the ability to persist using scheduled tasks. |
| T1071.001 Web Protocols |
Crutch has conducted C2 communications with a Dropbox account using the HTTP API. |
| T1074.001 Local Data Staging |
Crutch has staged stolen files in the |
| T1102.002 Bidirectional Communication |
Crutch can use Dropbox to receive commands and upload stolen data. |
| T1119 Automated Collection |
Crutch can automatically monitor removable drives in a loop and copy interesting files. |
| T1120 Peripheral Device Discovery |
Crutch can monitor for removable drives being plugged into the compromised machine. |
| T1560.001 Archive via Utility |
Crutch has used the WinRAR utility to compress and encrypt stolen files. |
| T1567.002 Exfiltration to Cloud Storage |
Crutch has exfiltrated stolen data to Dropbox. |
| T1574.001 DLL |
Crutch can persist via DLL search order hijacking on Google Chrome, Mozilla Firefox, or Microsoft OneDrive. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.