TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Slave Malware Analysis: Evolving From IBAN Swaps to Persistent Webinjects

2015-06-24 · Read original ↗

ATT&CK techniques detected

1 predictions
T1547.001Registry Run Keys / Startup Folder
99%
"data \ startup \. the malware then sets a startup registry key for sys. exe and starts the sys. exe process. to maintain its stealthy browser infection method after each reboot, slave creates a registry key with a random name, disguised as " internet explorer ", which will automa…"

Summary

Slave is financial malware written in Visual Basic. Since 2015 it has evolved from relatively simple IBAN swapping.