S0272 NDiskMonitor
NDiskMonitor is a custom backdoor written in .NET that appears to be unique to Patchwork. 1
Item | Value |
---|---|
ID | S0272 |
Associated Names | |
Type | MALWARE |
Version | 1.1 |
Created | 17 October 2018 |
Last Modified | 30 March 2020 |
Navigation Layer | View In ATT&CK® Navigator |
Techniques Used
Domain | ID | Name | Use |
---|---|---|---|
enterprise | T1573 | Encrypted Channel | - |
enterprise | T1573.001 | Symmetric Cryptography | NDiskMonitor uses AES to encrypt certain information sent over its C2 channel.1 |
enterprise | T1083 | File and Directory Discovery | NDiskMonitor can obtain a list of all files and directories as well as logical drives.1 |
enterprise | T1105 | Ingress Tool Transfer | NDiskMonitor can download and execute a file from given URL.1 |
enterprise | T1082 | System Information Discovery | NDiskMonitor obtains the victim computer name and encrypts the information to send over its C2 channel.1 |
enterprise | T1033 | System Owner/User Discovery | NDiskMonitor obtains the victim username and encrypts the information to send over its C2 channel.1 |
Groups That Use This Software
ID | Name | References |
---|---|---|
G0040 | Patchwork | 1 |