Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
QakBot can use a variety of commands, including esentutl.exe to steal sensitive data from Internet Explorer and Microsoft Edge, to acquire information that is subsequently exfiltrated. |
| T1010 Application Window Discovery |
QakBot has the ability to enumerate windows on a compromised host. |
| T1016 System Network Configuration Discovery |
QakBot can use |
| T1016.001 Internet Connection Discovery |
QakBot can measure the download speed on a targeted host. |
| T1018 Remote System Discovery |
QakBot can identify remote systems through the |
| T1027 Obfuscated Files or Information |
QakBot has hidden code within Excel spreadsheets by turning the font color to white and splitting it across multiple cells. |
| T1027.001 Binary Padding |
QakBot can use large file sizes to evade detection. |
| T1027.002 Software Packing |
QakBot can encrypt and pack malicious payloads. |
| T1027.005 Indicator Removal from Tools |
QakBot can make small changes to itself in order to change its checksum and hash value. |
| T1027.006 HTML Smuggling |
QakBot has been delivered in ZIP files via HTML smuggling. |
| T1027.010 Command Obfuscation |
QakBot can use obfuscated and encoded scripts. |
| T1027.011 Fileless Storage |
QakBot can store its configuration information in a randomly named subkey under |
| T1033 System Owner/User Discovery |
QakBot can identify the user name on a compromised system. |
| T1036.008 Masquerade File Type |
The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon. |
| T1041 Exfiltration Over C2 Channel |
QakBot can send stolen information to C2 nodes including passwords, accounts, and emails. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.