Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols | |
Enterprise | T1543 | .001 | Create or Modify System Process: Launch Agent |
The Komplex trojan creates a persistent launch agent called with |
Enterprise | T1573 | .001 | Encrypted Channel: Symmetric Cryptography |
The Komplex C2 channel uses an 11-byte XOR algorithm to hide data.[2] |
Enterprise | T1564 | .001 | Hide Artifacts: Hidden Files and Directories |
The Komplex payload is stored in a hidden directory at |
Enterprise | T1070 | .004 | Indicator Removal on Host: File Deletion | |
Enterprise | T1057 | Process Discovery |
The OsInfo function in Komplex collects a running process list.[2] |
|
Enterprise | T1033 | System Owner/User Discovery |
The OsInfo function in Komplex collects the current running username.[2] |
ID | Name | References |
---|---|---|
G0007 | APT28 |