Files
MBCProject-mbc-markdown/impact/generate-traffic-from-victim.md
T
Ryan Xu f7d92d59fa Staging (#124)
- Updating capa detection in behaviors
- Newsletter
- Conti malware
- pafish faq
2023-09-20 15:57:32 -04:00

2.6 KiB

ID E1643
Objective(s) Impact
Related ATT&CK Techniques Generate Traffic from Victim (T1643)
Impact Type Breach
Version 2.0
Created 1 August 2019
Last Modified 12 June 2023

Generate Traffic from Victim

Malware may generate traffic from the victim system such as clicks of advertising links that generate fraudulent ad revenue. The ATT&CK technique, Generate Traffic from Victim (T1643), is only associated with the mobile platform, but the behavior is applicable to other platforms as well.

Methods

Name ID Description
Advertisement Replacement Fraud E1643.m02 Malware injects ad windows onto websites the user views. [2]
Click Hijacking E1643.m01 Malware alters DNS server settings to route to a rogue DNS server: when the user clicks on a search result link displayed through a search engine query, malware re-routes the user to different website. Instead of going to the requested site, the user is taken to an alternate website such that the click triggers payment to the threat actor. [1] This method is related to Unprotect technique U0904.

Use in Malware

Name Date Method Description
DNSChanger 2011 E1643.m02 Malware alters DNS server settings to route to a rogue DNS server for the purpose of click hijacking. [1]
Kovter 2016 -- Kovter performs click-fraud. [4]
YiSpecter 2015 E1643.m02 The malware displays brief advertisements whenever the user opens applications on their phone. [5]

References

[1] https://www.huffingtonpost.com/2011/11/09/click-hijack-hackers-online-ad-scam_n_1084497.html

[2] https://www.fipp.com/news/insightnews/what-are-the-nine-types-of-digital-ad-fraud

[3] https://www.bleepingcomputer.com/virus-removal/remove-kovter-trojan

[4] https://unit42.paloaltonetworks.com/yispecter-first-ios-malware-attacks-non-jailbroken-ios-devices-by-abusing-private-apis/

[5] https://blog.malwarebytes.com/threat-analysis/2016/07/untangling-kovter/