{"description": "Enterprise techniques used by KONNI, ATT&CK software S0356 v1.4", "name": "KONNI (S0356)", "domain": "enterprise-attack", "versions": {"layer": "4.3", "attack": "10", "navigator": "4.5"}, "techniques": [{"techniqueID": "T1548", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1548.002", "showSubtechniques": true, "comment": "[KONNI](https://attack.mitre.org/software/S0356) bypassed UAC with the \u201cAlwaysNotify\u201d settings.(Citation: Medium KONNI Jan 2020)"}, {"techniqueID": "T1134", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1134.002", "showSubtechniques": true, "comment": "[KONNI](https://attack.mitre.org/software/S0356) has duplicated the token of a high integrity process to spawn an instance of cmd.exe under an impersonated user.(Citation: Medium KONNI Jan 2020)"}, {"techniqueID": "T1071", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1071.001", "showSubtechniques": true, "comment": "[KONNI](https://attack.mitre.org/software/S0356) has used HTTP for C2.(Citation: Talos Konni May 2017)"}, {"techniqueID": "T1547", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1547.001", "showSubtechniques": true, "comment": "A version of [KONNI](https://attack.mitre.org/software/S0356) drops a Windows shortcut into the Startup folder to establish persistence.(Citation: Talos Konni May 2017)"}, {"score": 1, "techniqueID": "T1547.009", "showSubtechniques": true, "comment": "A version of [KONNI](https://attack.mitre.org/software/S0356) drops a Windows shortcut on the victim\u2019s machine to establish persistence.(Citation: Talos Konni May 2017)"}, {"score": 1, "techniqueID": "T1115", "showSubtechniques": false, "comment": "[KONNI](https://attack.mitre.org/software/S0356) had a feature to steal data from the clipboard.(Citation: Talos Konni May 2017)"}, {"techniqueID": "T1059", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1059.001", "showSubtechniques": true, "comment": "[KONNI](https://attack.mitre.org/software/S0356) used PowerShell to download and execute a specific 64-bit version of the malware.(Citation: Talos Konni May 2017)"}, {"score": 1, "techniqueID": "T1059.003", "showSubtechniques": true, "comment": "[KONNI](https://attack.mitre.org/software/S0356) has used cmd.exe execute arbitrary commands on the infected host across different stages of the infection change.(Citation: Talos Konni May 2017)(Citation: Medium KONNI Jan 2020)"}, {"techniqueID": "T1555", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1555.003", "showSubtechniques": true, "comment": "[KONNI](https://attack.mitre.org/software/S0356) can steal profiles (containing credential information) from Firefox, Chrome, and Opera.(Citation: Talos Konni May 2017)"}, {"techniqueID": "T1132", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1132.001", "showSubtechniques": true, "comment": "[KONNI](https://attack.mitre.org/software/S0356) has used a custom base64 key to encode stolen data before exfiltration.(Citation: Medium KONNI Jan 2020)"}, {"score": 1, "techniqueID": "T1140", "showSubtechniques": false, "comment": "[KONNI](https://attack.mitre.org/software/S0356) has used certutil to download and decode base64 encoded strings.(Citation: Medium KONNI Jan 2020) "}, {"techniqueID": "T1546", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1546.015", "showSubtechniques": true, "comment": "[KONNI](https://attack.mitre.org/software/S0356) has modified ComSysApp service to load the malicious DLL payload.(Citation: Medium KONNI Jan 2020)"}, {"techniqueID": "T1048", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1048.003", "showSubtechniques": true, "comment": "[KONNI](https://attack.mitre.org/software/S0356) has used FTP to exfiltrate reconnaissance data out.(Citation: Medium KONNI Jan 2020)"}, {"score": 1, "techniqueID": "T1083", "showSubtechniques": false, "comment": "A version of [KONNI](https://attack.mitre.org/software/S0356) searches for filenames created with a previous version of the malware, suggesting different versions targeted the same victims and the versions may work together.(Citation: Talos Konni May 2017)"}, {"techniqueID": "T1070", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1070.004", "showSubtechniques": true, "comment": "[KONNI](https://attack.mitre.org/software/S0356) can delete files.(Citation: Talos Konni May 2017)"}, {"score": 1, "techniqueID": "T1105", "showSubtechniques": false, "comment": "[KONNI](https://attack.mitre.org/software/S0356) can download files and execute them on the victim\u2019s machine.(Citation: Talos Konni May 2017)"}, {"techniqueID": "T1056", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1056.001", "showSubtechniques": true, "comment": "[KONNI](https://attack.mitre.org/software/S0356) has the capability to perform keylogging.(Citation: Talos Konni May 2017)"}, {"techniqueID": "T1036", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1036.005", "showSubtechniques": true, "comment": "[KONNI](https://attack.mitre.org/software/S0356) creates a shortcut called \"Anti virus service.lnk\" in an apparent attempt to masquerade as a legitimate file.(Citation: Talos Konni May 2017)"}, {"score": 1, "techniqueID": "T1112", "showSubtechniques": false, "comment": "[KONNI](https://attack.mitre.org/software/S0356) has modified registry keys of ComSysApp service and Svchost on the machine to gain persistence.(Citation: Medium KONNI Jan 2020)"}, {"score": 1, "techniqueID": "T1057", "showSubtechniques": false, "comment": "[KONNI](https://attack.mitre.org/software/S0356) has used tasklist.exe to get a snapshot of the current processes\u2019 state of the target machine.(Citation: Medium KONNI Jan 2020)"}, {"score": 1, "techniqueID": "T1113", "showSubtechniques": false, "comment": "[KONNI](https://attack.mitre.org/software/S0356) can take screenshots of the victim\u2019s machine.(Citation: Talos Konni May 2017)"}, {"techniqueID": "T1218", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1218.011", "showSubtechniques": true, "comment": "[KONNI](https://attack.mitre.org/software/S0356) has used Rundll32 to execute its loader for privilege escalation purposes.(Citation: Medium KONNI Jan 2020)"}, {"score": 1, "techniqueID": "T1082", "showSubtechniques": false, "comment": "[KONNI](https://attack.mitre.org/software/S0356) can gather the OS version, architecture information, connected drives, hostname, and computer name from the victim\u2019s machine and has used systeminfo.exe to get a snapshot of the current system state of the target machine.(Citation: Talos Konni May 2017)(Citation: Medium KONNI Jan 2020)"}, {"score": 1, "techniqueID": "T1016", "showSubtechniques": false, "comment": "[KONNI](https://attack.mitre.org/software/S0356) can collect the IP address from the victim\u2019s machine.(Citation: Talos Konni May 2017)"}, {"score": 1, "techniqueID": "T1033", "showSubtechniques": false, "comment": "[KONNI](https://attack.mitre.org/software/S0356) can collect the username from the victim\u2019s machine.(Citation: Talos Konni May 2017)"}], "gradient": {"colors": ["#ffffff", "#66b1ff"], "minValue": 0, "maxValue": 1}, "legendItems": [{"label": "used by KONNI", "color": "#66b1ff"}]}