Malware.View on attack.mitre.org
MoleNet is a downloader tool with backdoor capabilities that has been observed in use since at least 2019.
| Technique | Procedure example |
|---|---|
| T1047 Windows Management Instrumentation |
MoleNet can perform WMI commands on the system. |
| T1059.001 PowerShell |
MoleNet can use PowerShell to set persistence. |
| T1059.003 Windows Command Shell |
MoleNet can execute commands via the command line utility. |
| T1082 System Information Discovery |
MoleNet can collect information about the about the system. |
| T1105 Ingress Tool Transfer |
MoleNet can download additional payloads from the C2. |
| T1518.001 Security Software Discovery |
MoleNet can use WMI commands to check the system for firewall and antivirus software. |
| T1547.001 Registry Run Keys / Startup Folder |
MoleNet can achieve persitence on the infected machine by setting the Registry run key. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.