Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
KEYPLUG can use a hardcoded one-byte XOR encoded configuration file. |
| T1071.001 Web Protocols |
KEYPLUG has the ability to communicate over HTTP and WebSocket Protocol (WSS) for C2. |
| T1090 Proxy |
KEYPLUG has used Cloudflare CDN associated infrastructure to redirect C2 communications to malicious domains. |
| T1095 Non-Application Layer Protocol |
KEYPLUG can use TCP and KCP (KERN Communications Protocol) over UDP for C2 communication. |
| T1102.001 Dead Drop Resolver |
The KEYPLUG Windows variant has retrieved C2 addresses from encoded data in posts on tech community forums. |
| T1124 System Time Discovery |
KEYPLUG can obtain the current tick count of an infected computer. |
| T1140 Deobfuscate/Decode Files or Information |
KEYPLUG can decode its configuration file to determine C2 protocols. |
| T1573.002 Asymmetric Cryptography |
KEYPLUG can use TLS-encrypted WebSocket Protocol (WSS) for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.