If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/software/S0098 - T9000, Software S0098 | MITRE .

site address: attack.mitre.org/software/S0098 redirected to: attack.mitre.org/software/S0098

site title: T9000, Software S0098 MITRE ATT&CK®

Our opinion (on Monday 24 August 2026 11:22:56 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

t9000, techniques, used, references, enterprise, layer,

Text of the page (most frequently used words):
the (22), #enterprise (19), t9000 (18), and (16), att (11), all (10), software (8), data (7), system (7), discovery (7), during (6), installation (6), windows (6), ics (5), mobile (5), none (5), techniques (5), mitre (4), uses (4), skype (4), encrypted (4), gathers (4), beacons (4), user (4), for (4), dll (4), version (4), are (3), cti (3), defenses (3), 2016 (3), april (3), audio (3), video (3), appdata (3), intel (3), capture (3), files (3), microsoft (3), used (3), malware (3), that (3), 2026 (2), corporation (2), use (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), core (2), objects (2), backdoor (2), retrieved (2), api (2), record (2), calls (2), writes (2), time (2), username (2), will (2), also (2), gather (2), running (2), bit (2), information (2), security (2), 001 (2), can (2), byte (2), xor (2), searches (2), removable (2), storage (2), devices (2), process (2), load (2), execution (2), victim (2), its (2), resn32 (2), hklm (2), currentversion (2), with (2), collected (2), archive (2), s0098 (2), about (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sub, grunzweig, miller, osborn, february, advanced, modular, complex, anti, analysis, moran, lanstein, 2014, march, spear, phishing, news, cycle, apt, actors, leverage, interest, disappearance, malaysian, flight, 370, references, t1125, t1124, logged, account, processes, determine, owner, t1033, mac, addresses, network, configuration, t1016, operating, build, number, cpu, architecture, t1082, performs, checks, various, antivirus, products, t1518, take, screenshots, desktop, target, application, saving, them, directories, one, dat, screen, t1113, through, connected, drives, peripheral, device, t1120, drops, copy, legitimate, binary, igfxtray, exe, executable, contains, side, loading, weakness, which, portion, hijack, flow, t1574, meets, certain, criteria, appinit_dll, functionality, achieve, persistence, ensuring, every, mode, spawned, malicious, does, this, creating, following, registry, keys, loadappinit_dlls, 0x1, appinit_dlls, appinit, dlls, event, triggered, 010, t1546, pre, defined, list, file, extensions, doc, xls, pptx, xlsx, any, matching, written, local, directory, docx, ppt, automated, collection, t1119, t1123, encrypts, using, single, key, via, custom, method, 003, t1560, name, domain, view, download, layer, navigator, layers, live, permalink, 2025, last, modified, may, 2017, created, platforms, type, newer, variant, t5000, family, known, plat1, primary, function, has, been, multiple, targeted, attacks, against, based, organizations, home, open, join, october, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, get, started, detections,


Text of the page (random words):
t9000 software s0098 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home software t9000 t9000 t9000 is a backdoor that is a newer variant of the t5000 malware family also known as plat1 its primary function is to gather information about the victim it has been used in multiple targeted attacks against u s based organizations 1 2 id s0098 ⓘ type malware ⓘ platforms windows version 1 1 created 31 may 2017 last modified 25 april 2025 version permalink live version att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1560 003 archive collected data archive via custom method t9000 encrypts collected data using a single byte xor key 2 enterprise t1123 audio capture t9000 uses the skype api to record audio and video calls it writes encrypted data to appdata intel skype 2 enterprise t1119 automated collection t9000 searches removable storage devices for files with a pre defined list of file extensions e g doc ppt xls docx pptx xlsx any matching files are encrypted and written to a local user directory 2 enterprise t1546 010 event triggered execution appinit dlls if a victim meets certain criteria t9000 uses the appinit_dll functionality to achieve persistence by ensuring that every user mode process that is spawned will load its malicious dll resn32 dll it does this by creating the following registry keys hklm software microsoft windows nt currentversion windows appinit_dlls appdata intel resn32 dll and hklm software microsoft windows nt currentversion windows loadappinit_dlls 0x1 2 enterprise t1574 001 hijack execution flow dll during the t9000 installation process it drops a copy of the legitimate microsoft binary igfxtray exe the executable contains a side loading weakness which is used to load a portion of the malware 2 enterprise t1120 peripheral device discovery t9000 searches through connected drives for removable storage devices 2 enterprise t1113 screen capture t9000 can take screenshots of the desktop and target application windows saving them to user directories as one byte xor encrypted dat files 2 enterprise t1518 001 software discovery security software discovery t9000 performs checks for various antivirus and security products during installation 2 enterprise t1082 system information discovery t9000 gathers and beacons the operating system build number and cpu architecture 32 bit 64 bit during installation 2 enterprise t1016 system network configuration discovery t9000 gathers and beacons the mac and ip addresses during installation 2 enterprise t1033 system owner user discovery t9000 gathers and beacons the username of the logged in account during installation it will also gather the username of running processes to determine if it is running as system 2 enterprise t1124 system time discovery t9000 gathers and beacons the system time during installation 2 enterprise t1125 video capture t9000 uses the skype api to record audio and video calls it writes encrypted data to appdata intel skype 2 references moran n and lanstein a 2014 march 25 spear phishing the news cycle apt actors leverage interest in the disappearance of malaysian flight mh 370 retrieved april 15 2016 grunzweig j and miller osborn j 2016 february 4 t9000 advanced modular backdoor uses complex anti analysis techniques retrieved april 15 2016 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 60 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


The site also has 1 references to other resources (not html/xhtml )

 attack.mitre.org/software/S0098/S0098___.json  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/software/S0098
X-GitHub-Request-Id 2F40:1459C1:65B1903:6697631:6A8C298F
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Mon, 24 Aug 2026 11:22:55 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290021-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787570576.502998,VS0,VE98
Vary Accept-Encoding
X-Fastly-Request-ID b7ecd3529d440ccb78382161e70759500483b897
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/software/S0098/
access-control-allow-origin *
expires Mon, 24 Aug 2026 11:32:55 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 8DA8:19A3F5:687B7D0:6961C33:6A8C298F
x-github-edge-region fra
accept-ranges bytes
age 0
date Mon, 24 Aug 2026 11:22:55 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290043-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787570576.635023,VS0,VE102
vary Accept-Encoding
x-fastly-request-id 24a3ff95db455337f7f7cadbce299b613b1c46ec
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
last-modified Fri, 07 Aug 2026 14:24:19 GMT
access-control-allow-origin *
etag W/ 6a75ea93-cfd1
expires Mon, 24 Aug 2026 11:32:55 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id E7E4:15B2:3E6AB03:3EFD257:6A8C298F
x-github-edge-region fra
accept-ranges bytes
age 0
date Mon, 24 Aug 2026 11:22:55 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290043-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787570576.748107,VS0,VE109
vary Accept-Encoding
x-fastly-request-id ab22d52a224fb0de52914d2392d5cad061effa0d
content-length 8059

Meta Tags

title="T9000, Software S0098 | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size8059
load time (s)0.591418
redirect count2
speed download13636
server IP 185.199.109.153
* all occurrences of the string "http://" have been changed to "htt???/"