JHUHUGIT — Malware Profile
JHUHUGIT is malware used by APT28. It is based on Carberp source code and serves as reconnaissance malware.
MITRE ATT&CK techniques (20)
- T1008 Fallback Channels
- T1016 System Network Configuration Discovery
- T1027.013 Encrypted/Encoded File
- T1037.001 Logon Script (Windows)
- T1053.005 Scheduled Task
- T1055 Process Injection
- T1057 Process Discovery
- T1059.003 Windows Command Shell
- T1068 Exploitation for Privilege Escalation
- T1070.004 File Deletion
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1113 Screen Capture
- T1115 Clipboard Data
- T1132.001 Standard Encoding
- T1218.011 Rundll32
- T1543.003 Windows Service
- T1546.015 Component Object Model Hijacking
- T1547.001 Registry Run Keys / Startup Folder
- T1680 Local Storage Discovery