MATRYOSHKA

MATRYOSHKAMatryoshka

Description

Their most commonly used initial attack vector is a simple, yet alarmingly effective, spearphishing attack, infecting unsuspecting victims via a malicious email attachment (usually an executable that has been disguised as something else). From there, Matryoshka runs second stage malware via a dropper and covertly installs a Remote Access Toolkit (RAT). This is done using a reflective loader technique that allows the malware to run in process memory, rather than being written to disk. This not only hides the install of the RAT but also ensures that the RAT will be ‘reinstalled’ after system restart.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
Matroska
Software
Marozka
Software
Katyusha
Software
Chekyshka
Software
Prikormka
Software
RadRAT
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.