Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
ANDROMEDA has been installed to `C:\Temp\TrustedInstaller.exe` to mimic a legitimate Windows installer service. |
| T1036.008 Masquerade File Type |
ANDROMEDA has been delivered through a LNK file disguised as a folder. |
| T1055 Process Injection |
ANDROMEDA can inject into the `wuauclt.exe` process to perform C2 actions. |
| T1071.001 Web Protocols |
ANDROMEDA has the ability to make GET requests to download files from C2. |
| T1091 Replication Through Removable Media |
ANDROMEDA has been spread via infected USB keys. |
| T1105 Ingress Tool Transfer |
ANDROMEDA can download additional payloads from C2. |
| T1547.001 Registry Run Keys / Startup Folder |
ANDROMEDA can establish persistence by dropping a sample of itself to `C:\ProgramData\Local Settings\Temp\mskmde.com` and adding a Registry run key to execute every time a user logs on. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.