Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1041 Exfiltration Over C2 Channel |
ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files. |
| T1059.003 Windows Command Shell |
ODAgent can execute a specified command line passed via API. |
| T1070.004 File Deletion |
ODAgent can delete payloads and files used to pass C2 commands from remotely hosted cloud accounts. |
| T1083 File and Directory Discovery |
ODAgent can identify the current working directory. |
| T1102.002 Bidirectional Communication |
ODAgent can use the Microsoft Graph API to access an attacker-controlled OneDrive account and retrieve payloads and backdoor commands. |
| T1105 Ingress Tool Transfer |
ODAgent has the ability to download and execute files on compromised systems. |
| T1106 Native API |
ODAgent can pass commands using native APIs. |
| T1140 Deobfuscate/Decode Files or Information |
ODAgent can Base64-decode and XOR decrypt received C2 commands. |
| T1567.002 Exfiltration to Cloud Storage |
ODAgent can use an attacker-controlled OneDrive account for exfiltration. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.