TAINTEDSCRIBE — Malware Profile
TAINTEDSCRIBE is a fully-featured beaconing implant integrated with command modules used by Lazarus Group. It was first reported in May 2020.
MITRE ATT&CK techniques (16)
- T1001.003 Protocol or Service Impersonation
- T1008 Fallback Channels
- T1018 Remote System Discovery
- T1027.001 Binary Padding
- T1036.005 Match Legitimate Resource Name or Location
- T1057 Process Discovery
- T1059.003 Windows Command Shell
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1083 File and Directory Discovery
- T1105 Ingress Tool Transfer
- T1124 System Time Discovery
- T1547.001 Registry Run Keys / Startup Folder
- T1560 Archive Collected Data
- T1573.001 Symmetric Cryptography
- T1680 Local Storage Discovery