ROAMINGHOUSE — Malware Profile
ROAMINGHOUSE is a dropper malware used by MirrorFace to extract and execute embedded payloads including UPPERCUT components.
MITRE ATT&CK techniques (11)
- T1027.013 Encrypted/Encoded File
- T1047 Windows Management Instrumentation
- T1137.001 Office Template Macros
- T1140 Deobfuscate/Decode Files or Information
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1480 Execution Guardrails
- T1497.002 User Activity Based Checks
- T1518.001 Security Software Discovery
- T1566.002 Spearphishing Link
- T1574.001 DLL