mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
f7d92d59fa
- Updating capa detection in behaviors - Newsletter - Conti malware - pafish faq
2.6 KiB
2.6 KiB
| ID | E1643 |
| Objective(s) | Impact |
| Related ATT&CK Techniques | Generate Traffic from Victim (T1643) |
| Impact Type | Breach |
| Version | 2.0 |
| Created | 1 August 2019 |
| Last Modified | 12 June 2023 |
Generate Traffic from Victim
Malware may generate traffic from the victim system such as clicks of advertising links that generate fraudulent ad revenue. The ATT&CK technique, Generate Traffic from Victim (T1643), is only associated with the mobile platform, but the behavior is applicable to other platforms as well.
Methods
| Name | ID | Description |
|---|---|---|
| Advertisement Replacement Fraud | E1643.m02 | Malware injects ad windows onto websites the user views. [2] |
| Click Hijacking | E1643.m01 | Malware alters DNS server settings to route to a rogue DNS server: when the user clicks on a search result link displayed through a search engine query, malware re-routes the user to different website. Instead of going to the requested site, the user is taken to an alternate website such that the click triggers payment to the threat actor. [1] This method is related to Unprotect technique U0904. |
Use in Malware
| Name | Date | Method | Description |
|---|---|---|---|
| DNSChanger | 2011 | E1643.m02 | Malware alters DNS server settings to route to a rogue DNS server for the purpose of click hijacking. [1] |
| Kovter | 2016 | -- | Kovter performs click-fraud. [4] |
| YiSpecter | 2015 | E1643.m02 | The malware displays brief advertisements whenever the user opens applications on their phone. [5] |
References
[1] https://www.huffingtonpost.com/2011/11/09/click-hijack-hackers-online-ad-scam_n_1084497.html
[2] https://www.fipp.com/news/insightnews/what-are-the-nine-types-of-digital-ad-fraud
[3] https://www.bleepingcomputer.com/virus-removal/remove-kovter-trojan
[4] https://unit42.paloaltonetworks.com/yispecter-first-ios-malware-attacks-non-jailbroken-ios-devices-by-abusing-private-apis/
[5] https://blog.malwarebytes.com/threat-analysis/2016/07/untangling-kovter/