Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
DRYHOOK has encrypted stolen credentials strings within a file using both Base64 and RC4 with a hard-coded key. |
| T1056.001 Keylogging |
DRYHOOK has captured user credentials and passwords in plaintext and has encrypted them in a stored file on the network device. |
| T1059.006 Python |
DRYHOOK is a Python-based script that executes within the victim environment. |
| T1059.008 Network Device CLI |
DRYHOOK has the ability to interact with Ivanti Connect Secure environments and to modify system components. |
| T1074.001 Local Data Staging |
DRYHOOK has stored stolen credentials for future use in the temp folder of a victimized Ivanti Connect Secure VPN device, specifically in the file location `/tmp/cmmmap.kumMW`. |
| T1222.002 Linux and Mac Permissions |
DRYHOOK has the ability to remount the filesystem as “read-write” to make changes and then restores it to “read-only” prior to killing processes to apply the modifications. |
| T1489 Service Stop |
DRYHOOK has terminated all instances of the `cgi-server` process before activating the modified DSAuth.pm file. |
| T1556 Modify Authentication Process |
DRYHOOK has intercepted and logged user credentials by modifying the Perl module in Ivanti Connect Secure VPN edge-devices located within `/home/perl/DSAuth.pm`. |
| T1556.004 Network Device Authentication |
DRYHOOK has patched victim appliances authentication routines to capture credentials in plaintext as users log in. |
| T1601 Modify System Image |
DRYHOOK has modified the Ivanti Connect Secure VPN authentication Perl module `DSAuth.pm` by reading its contents in the buffer, then finding and replacing select lines of code. |
| T1685 Disable or Modify Tools |
DRYHOOK has killed all instances of the `cgi-server` process in order for the modified Perl module to be activated. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.