Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
Mango contains a series of base64 encoded substrings. |
| T1033 System Owner/User Discovery |
Mango can collect the user name from a compromised system which is used to create a unique victim identifier. |
| T1041 Exfiltration Over C2 Channel |
Mango can use its HTTP C2 channel for exfiltration. |
| T1053.005 Scheduled Task |
Mango can create a scheduled task to run every 32 seconds to communicate with C2 and execute received commands. |
| T1071.001 Web Protocols |
Mango can retrieve C2 commands sent in HTTP responses. |
| T1082 System Information Discovery |
Mango can collect the machine name of a compromised system which is later used as part of a unique victim identifier. |
| T1083 File and Directory Discovery |
Mango can enumerate the contents of current working or other specified directories. |
| T1106 Native API |
Mango has the ability to use Native APIs. |
| T1132.001 Standard Encoding |
Mango can receive Base64-encoded commands from C2. |
| T1204.002 Malicious File |
Mango has been executed through a Microsoft Word document with a malicious macro. |
| T1573.001 Symmetric Cryptography |
Mango can receive XOR-encrypted commands from C2. |
| T1573.002 Asymmetric Cryptography |
Mango can use TLS to encrypt C2 communications. |
| T1685 Disable or Modify Tools |
Mango contains an unused capability to block endpoint security solutions from loading user-mode code hooks via a DLL in a specified process by using the `UpdateProcThreadAttribute API` to set the `PROC_THREAD_ATTRIBUTE_MITIGATION_POLICY` to `PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON` for an identified process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.