Matryoshka — Malware Profile
Matryoshka is a malware framework used by CopyKittens that consists of a dropper, loader, and RAT. It has multiple versions; v1 was seen in the wild from July 2016 until January 2017. v2 has fewer commands and other minor differences.
MITRE ATT&CK techniques (10)
- T1027 Obfuscated Files or Information
- T1053.005 Scheduled Task
- T1055.001 Dynamic-link Library Injection
- T1056.001 Keylogging
- T1059 Command and Scripting Interpreter
- T1071.004 DNS
- T1113 Screen Capture
- T1218.011 Rundll32
- T1547.001 Registry Run Keys / Startup Folder
- T1555 Credentials from Password Stores