Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
LitePower can query the Registry for keys added to execute COM hijacking. |
| T1033 System Owner/User Discovery |
LitePower can determine if the current user has admin privileges. |
| T1041 Exfiltration Over C2 Channel |
LitePower can send collected data, including screenshots, over its C2 channel. |
| T1053.005 Scheduled Task |
LitePower can create a scheduled task to enable persistence mechanisms. |
| T1059.001 PowerShell |
LitePower can use a PowerShell script to execute commands. |
| T1071.001 Web Protocols |
LitePower can use HTTP and HTTPS for C2 communications. |
| T1082 System Information Discovery |
LitePower has the ability to enumerate the OS architecture. |
| T1105 Ingress Tool Transfer |
LitePower has the ability to download payloads containing system commands to a compromised host. |
| T1106 Native API |
LitePower can use various API calls. |
| T1113 Screen Capture |
LitePower can take system screenshots and save them to `%AppData%`. |
| T1518.001 Security Software Discovery |
LitePower can identify installed AV software. |
| T1680 Local Storage Discovery |
LitePower has the ability to list local drives. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.