Meta tags:
Headings (most frequently used words):
t9000, techniques, used, references, enterprise, layer,
Text of the page (most frequently used words):
the (22), #enterprise (19), t9000 (18), and (16), att (11), all (10), software (8), data (7), system (7), discovery (7), during (6), installation (6), windows (6), ics (5), mobile (5), none (5), techniques (5), mitre (4), uses (4), skype (4), encrypted (4), gathers (4), beacons (4), user (4), for (4), dll (4), version (4), are (3), cti (3), defenses (3), 2016 (3), april (3), audio (3), video (3), appdata (3), intel (3), capture (3), files (3), microsoft (3), used (3), malware (3), that (3), 2026 (2), corporation (2), use (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), core (2), objects (2), backdoor (2), retrieved (2), api (2), record (2), calls (2), writes (2), time (2), username (2), will (2), also (2), gather (2), running (2), bit (2), information (2), security (2), 001 (2), can (2), byte (2), xor (2), searches (2), removable (2), storage (2), devices (2), process (2), load (2), execution (2), victim (2), its (2), resn32 (2), hklm (2), currentversion (2), with (2), collected (2), archive (2), s0098 (2), about (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sub, grunzweig, miller, osborn, february, advanced, modular, complex, anti, analysis, moran, lanstein, 2014, march, spear, phishing, news, cycle, apt, actors, leverage, interest, disappearance, malaysian, flight, 370, references, t1125, t1124, logged, account, processes, determine, owner, t1033, mac, addresses, network, configuration, t1016, operating, build, number, cpu, architecture, t1082, performs, checks, various, antivirus, products, t1518, take, screenshots, desktop, target, application, saving, them, directories, one, dat, screen, t1113, through, connected, drives, peripheral, device, t1120, drops, copy, legitimate, binary, igfxtray, exe, executable, contains, side, loading, weakness, which, portion, hijack, flow, t1574, meets, certain, criteria, appinit_dll, functionality, achieve, persistence, ensuring, every, mode, spawned, malicious, does, this, creating, following, registry, keys, loadappinit_dlls, 0x1, appinit_dlls, appinit, dlls, event, triggered, 010, t1546, pre, defined, list, file, extensions, doc, xls, pptx, xlsx, any, matching, written, local, directory, docx, ppt, automated, collection, t1119, t1123, encrypts, using, single, key, via, custom, method, 003, t1560, name, domain, view, download, layer, navigator, layers, live, permalink, 2025, last, modified, may, 2017, created, platforms, type, newer, variant, t5000, family, known, plat1, primary, function, has, been, multiple, targeted, attacks, against, based, organizations, home, open, join, october, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, get, started, detections,
Text of the page (random words):
t9000 software s0098 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home software t9000 t9000 t9000 is a backdoor that is a newer variant of the t5000 malware family also known as plat1 its primary function is to gather information about the victim it has been used in multiple targeted attacks against u s based organizations 1 2 id s0098 ⓘ type malware ⓘ platforms windows version 1 1 created 31 may 2017 last modified 25 april 2025 version permalink live version att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1560 003 archive collected data archive via custom method t9000 encrypts collected data using a single byte xor key 2 enterprise t1123 audio capture t9000 uses the skype api to record audio and video calls it writes encrypted data to appdata intel skype 2 enterprise t1119 automated collection t9000 searches removable storage devices for files with a pre defined list of file extensions e g doc ppt xls docx pptx xlsx any matching files are encrypted and written to a local user directory 2 enterprise t1546 010 event triggered execution appinit dlls if a victim meets certain criteria t9000 uses the appinit_dll functionality to achieve persistence by ensuring that every user mode process that is spawned will load its malicious dll resn32 dll it does this by creating the following registry keys hklm software microsoft windows nt currentversion windows appinit_dlls appdata intel resn32 dll and hklm software microsoft windows nt currentversion windows loadappinit_dlls 0x1 2 enterprise t1574 001 hijack execution flow dll during the t9000 installation process it drops a copy of the legitimate microsoft binary igfxtray exe the executable contains a side loading weakness which is used to load a portion of the malware 2 enterprise t1120 peripheral device discovery t9000 searches through connected drives for removable storage devices 2 enterprise t1113 screen capture t9000 can take screenshots of the desktop and target application windows saving them to user directories as one byte xor encrypted dat files 2 enterprise t1518 001 software discovery security software discovery t9000 performs checks for various antivirus and security products during installation 2 enterprise t1082 system information discovery t9000 gathers and beacons the operating system build number and cpu architecture 32 bit 64 bit during installation 2 enterprise t1016 system network configuration discovery t9000 gathers and beacons the mac and ip addresses during installation 2 enterprise t1033 system owner user discovery t9000 gathers and beacons the username of the logged in account during installation it will also gather the username of running processes to determine if it is running as system 2 enterprise t1124 system time discovery t9000 gathers and beacons the system time during installation 2 enterprise t1125 video capture t9000 uses the skype api to record audio and video calls it writes encrypted data to appdata intel skype 2 references moran n and lanstein a 2014 march 25 spear phishing the news cycle apt actors leverage interest in the disappearance of malaysian flight mh 370 retrieved april 15 2016 grunzweig j and miller osborn j 2016 february 4 t9000 advanced modular backdoor uses complex anti analysis techniques retrieved april 15 2016 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|