Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Penquin can report the IP of the compromised host to attacker controlled infrastructure. |
| T1027.005 Indicator Removal from Tools |
Penquin can remove strings from binaries. |
| T1027.013 Encrypted/Encoded File |
Penquin has encrypted strings in the binary for obfuscation. |
| T1036.005 Match Legitimate Resource Name or Location |
Penquin has mimicked the Cron binary to hide itself on compromised systems. |
| T1040 Network Sniffing |
Penquin can sniff network traffic to look for packets matching specific conditions. |
| T1041 Exfiltration Over C2 Channel |
Penquin can execute the command code |
| T1053.003 Cron |
Penquin can use Cron to create periodic and pre-scheduled background jobs. |
| T1059.004 Unix Shell |
Penquin can execute remote commands using bash scripts. |
| T1070.004 File Deletion |
Penquin can delete downloaded executables after running them. |
| T1082 System Information Discovery |
Penquin can report the file system type of a compromised host to C2. |
| T1083 File and Directory Discovery |
Penquin can use the command code |
| T1095 Non-Application Layer Protocol |
The Penquin C2 mechanism is based on TCP and UDP packets. |
| T1105 Ingress Tool Transfer |
Penquin can execute the command code |
| T1205 Traffic Signaling |
Penquin will connect to C2 only after sniffing a "magic packet" value in TCP or UDP packets matching specific conditions. |
| T1205.002 Socket Filters |
Penquin installs a `TCP` and `UDP` filter on the `eth0` interface. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.