LP-Notes — Malware Profile
LP-Notes is a C/C++ Windows credential stealer used by MuddyWater. LP-Notes was named after the `lp-notes.txt` file that is used to store stolen credentials.
MITRE ATT&CK techniques (11)
- T1027.007 Dynamic API Resolution
- T1027.013 Encrypted/Encoded File
- T1056.002 GUI Input Capture
- T1057 Process Discovery
- T1059.001 PowerShell
- T1074.001 Local Data Staging
- T1078 Valid Accounts
- T1106 Native API
- T1134.001 Token Impersonation/Theft
- T1140 Deobfuscate/Decode Files or Information
- T1560 Archive Collected Data