Malware.View on attack.mitre.org
MarkiRAT is a remote access Trojan (RAT) compiled with Visual Studio that has been used by Ferocious Kitten since at least 2015.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
MarkiRAT can upload data from the victim's machine to the C2 server. |
| T1033 System Owner/User Discovery |
MarkiRAT can retrieve the victim’s username. |
| T1036.005 Match Legitimate Resource Name or Location |
MarkiRAT can masquerade as |
| T1041 Exfiltration Over C2 Channel |
MarkiRAT can exfiltrate locally stored data via its C2. |
| T1056.001 Keylogging |
MarkiRAT can capture all keystrokes on a compromised host. |
| T1057 Process Discovery |
MarkiRAT can search for different processes on a system. |
| T1059.003 Windows Command Shell |
MarkiRAT can utilize cmd.exe to execute commands in a victim's environment. |
| T1071.001 Web Protocols |
MarkiRAT can initiate communication over HTTP/HTTPS for its C2 server. |
| T1074.001 Local Data Staging |
MarkiRAT can store collected data locally in a created .nfo file. |
| T1082 System Information Discovery |
MarkiRAT can obtain the computer name from a compromised host. |
| T1083 File and Directory Discovery |
MarkiRAT can look for files carrying specific extensions such as: .rtf, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pps, .ppsx, .txt, .gpg, .pkr, .kdbx, .key, and .jpb. |
| T1105 Ingress Tool Transfer |
MarkiRAT can download additional files and tools from its C2 server, including through the use of BITSAdmin. |
| T1106 Native API |
MarkiRAT can run the ShellExecuteW API via the Windows Command Shell. |
| T1113 Screen Capture |
MarkiRAT can capture screenshots that are initially saved as ‘scr.jpg’. |
| T1115 Clipboard Data |
MarkiRAT can capture clipboard content. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.