Attack Matrix
Story: Astaroth Banking Malware Abuses GitHub for Resilient Configurations
Identified Techniques: T1566 - Phishing, T1059 - Command and Scripting Interpreter, T1203, T1071 - Application Layer Protocol, T1040, T1055 - Process Injection, T1499, T1563
Note: Sub-techniques are displayed under their parent techniques in the matrix below.
Legend:
Standard Techniques
Techniques Identified in This Story
| Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
|---|---|---|---|---|---|---|---|---|---|---|---|
About MITRE ATT&CK®:
MITRE ATT&CK® is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&CK knowledge base is used as a foundation for the development of specific threat models and methodologies in the private sector, in government, and in the cybersecurity product and service community.