BLACKENERGY

BLACKENERGYBlackEnergy

Description

BlackEnergy is a trojan which has undergone significant functional changes since it was first publicly analysed by Arbor Networks in 2007. It has evolved from a relatively simple DDoS trojan into a relatively sophisticated piece of modern malware with a modular architecture, making it a suitable tool for sending spam and for online bank fraud, as well as for targeted attacks. BlackEnergy version 2, which featured rootkit techniques, was documented by SecureWorks in 2010. The targeted attacks recently discovered are proof that the trojan is still alive and kicking in 2014. We provide a technical analysis of the BlackEnergy family, focusing on novel functionality and the differences introduced by new lite variants. We describe the most notable aspects of the malware, including its techniques for bypassing UAC, defeating the signed driver requirement in Windows and a selection of BlackEnergy2 plug-ins used for parasitic file infections, network discovery and remote code execution and data collection.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
GreyEnergy
Software
BlackByte
Software
BlackKingdom
Software
BlackRose
Software
DarkGate
Software
BLACKCOFFEE
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.