🇰🇵

TraderTraitor

APT Group 9 zero-day CVEs ETDA ✓

Details

Origin 🇰🇵 KP
Last Updated 08 Nov 2023

Malware Families 2

gold_digger
hloader

MITRE ATT&CK 59

T1011.001 - Exfiltration Over Bluetooth T1021.001 - Remote Desktop Protocol T1027 - Obfuscated Files or Information T1027.002 - Software Packing T1041 - Exfiltration Over C2 Channel T1047 - Windows Management Instrumentation T1048.003 - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1059 - Command and Scripting Interpreter T1059.006 - Python T1068 - Exploitation for Privilege Escalation T1071 - Application Layer Protocol T1071.001 - Web Protocols T1074 - Data Staged T1078 - Valid Accounts T1078.003 - Local Accounts T1082 - System Information Discovery T1087 - Account Discovery T1095 - Non-Application Layer Protocol T1105 - Ingress Tool Transfer T1110 - Brute Force T1133 - External Remote Services T1134.002 - Create Process with Token T1189 - Drive-by Compromise T1190 - Exploit Public-Facing Application T1195 - Supply Chain Compromise T1199 - Trusted Relationship T1203 T1204 - User Execution T1204.002 - Malicious File T1210 - Exploitation of Remote Services T1219 - Remote Access Software T1486 - Data Encrypted for Impact T1499 - Endpoint Denial of Service T1518 - Software Discovery T1543 - Create or Modify System Process T1547.001 - Registry Run Keys / Startup Folder T1550 - Use Alternate Authentication Material T1552 - Unsecured Credentials T1553 - Subvert Trust Controls T1555 - Credentials from Password Stores T1561.001 - Disk Content Wipe T1566 - Phishing T1566.001 T1566.002 - Spearphishing Link T1567.002 - Exfiltration to Cloud Storage T1573.002 T1574.001 - DLL Search Order Hijacking T1574.012 - COR_PROFILER T1578 - Modify Cloud Compute Infrastructure T1580 - Cloud Infrastructure Discovery T1583 - Acquire Infrastructure T1584 - Compromise Infrastructure T1584.005 - Botnet T1587 - Develop Capabilities T1588 - Obtain Capabilities T1589 - Gather Victim Identity Information T1590 - Gather Victim Network Information T1608 - Stage Capabilities T1609 - Container Administration Command