Malware.View on attack.mitre.org
HiddenFace is a modular backdoor developed and used exclusively by MirrorFace since at least 2021. HiddenFace can communicate both actively and passively and has been used against political and academic targets.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
HiddenFace can upload files from the victim machine to C2 nodes. |
| T1008 Fallback Channels |
HiddenFace can use active and passive C2 modes that use different encryption algorithms and backdoor commands. |
| T1027.007 Dynamic API Resolution |
HiddenFace can dynamically resolve Windows APIs. |
| T1027.013 Encrypted/Encoded File |
HiddenFace has encrypted its payload with AES. |
| T1033 System Owner/User Discovery |
HiddenFace can collect the username associated with the compromised host. |
| T1053.005 Scheduled Task |
HiddenFace has used scheduled tasks for execution and persistence. |
| T1055 Process Injection |
HiddenFace can inject code directly into legitimate applications. |
| T1057 Process Discovery |
HiddenFace can check running processes against a list of blocklisted applications. |
| T1070.006 Timestomp |
HiddenFace can alter timestamps for directory content on targeted machines. |
| T1082 System Information Discovery |
HiddenFace can enumerate the hostname and username of the compromised system. |
| T1090.001 Internal Proxy |
HiddenFace can act as an internal HTTP proxy within the targeted environment. |
| T1095 Non-Application Layer Protocol |
HiddenFace can use a custom TCP protocol over Port 443 for C2. |
| T1105 Ingress Tool Transfer |
HiddenFace can download files from the C2 to victim systems. |
| T1112 Modify Registry |
HiddenFace can store its configuration file in the Registry. |
| T1140 Deobfuscate/Decode Files or Information |
HiddenFace has the ability to decrypt its payload prior to execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.