Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.010 Command Obfuscation |
KOCTOPUS has obfuscated scripts with the BatchEncryption tool. |
| T1036.005 Match Legitimate Resource Name or Location |
KOCTOPUS has been disguised as legitimate software programs associated with the travel and airline industries. |
| T1059.001 PowerShell |
KOCTOPUS has used PowerShell commands to download additional files. |
| T1059.003 Windows Command Shell |
KOCTOPUS has used `cmd.exe` and batch files for execution. |
| T1059.005 Visual Basic |
KOCTOPUS has used VBScript to call wscript to execute a PowerShell command. |
| T1070.009 Clear Persistence |
KOCTOPUS can delete created registry keys used for persistence as part of its cleanup procedure. |
| T1082 System Information Discovery |
KOCTOPUS has checked the OS version using `wmic.exe` and the `find` command. |
| T1090 Proxy |
KOCTOPUS has deployed a modified version of Invoke-Ngrok to expose open local ports to the Internet. |
| T1105 Ingress Tool Transfer |
KOCTOPUS has executed a PowerShell command to download a file to the system. |
| T1106 Native API |
KOCTOPUS can use the `LoadResource` and `CreateProcessW` APIs for execution. |
| T1112 Modify Registry |
KOCTOPUS has added and deleted keys from the Registry. |
| T1140 Deobfuscate/Decode Files or Information |
KOCTOPUS has deobfuscated itself before executing its commands. |
| T1204.001 Malicious Link |
KOCTOPUS has relied on victims clicking on a malicious link delivered via email. |
| T1204.002 Malicious File |
KOCTOPUS has relied on victims clicking a malicious document for execution. |
| T1547.001 Registry Run Keys / Startup Folder |
KOCTOPUS can set the AutoRun Registry key with a PowerShell command. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.