Malware.View on attack.mitre.org
StrifeWater is a remote-access tool that has been used by Moses Staff in the initial stages of their attacks since at least November 2021.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
StrifeWater can collect data from a compromised host. |
| T1033 System Owner/User Discovery |
StrifeWater can collect the user name from the victim's machine. |
| T1036.005 Match Legitimate Resource Name or Location |
StrifeWater has been named `calc.exe` to appear as a legitimate calculator program. |
| T1041 Exfiltration Over C2 Channel |
StrifeWater can send data and files from a compromised host to its C2 server. |
| T1053.005 Scheduled Task |
StrifeWater has create a scheduled task named `Mozilla\Firefox Default Browser Agent 409046Z0FF4A39CB` for persistence. |
| T1059.003 Windows Command Shell |
StrifeWater can execute shell commands using `cmd.exe`. |
| T1070.004 File Deletion |
StrifeWater can self delete to cover its tracks. |
| T1082 System Information Discovery |
StrifeWater can collect the OS version, architecture, and machine name to create a unique token for the infected host. |
| T1083 File and Directory Discovery |
StrifeWater can enumerate files on a compromised host. |
| T1105 Ingress Tool Transfer |
StrifeWater can download updates and auxiliary modules. |
| T1106 Native API |
StrifeWater can use a variety of APIs for execution. |
| T1113 Screen Capture |
StrifeWater has the ability to take screen captures. |
| T1124 System Time Discovery |
StrifeWater can collect the time zone from the victim's machine. |
| T1497.003 Time Based Checks |
StrifeWater can modify its sleep time responses from the default of 20-22 seconds. |
| T1573.001 Symmetric Cryptography |
StrifeWater can encrypt C2 traffic using XOR with a hard coded key. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.