| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1189 | 浏览器攻击 |
KARAE was distributed through torrent file-sharing websites to South Korean victims, using a YouTube video downloader application as a lure.[1] |
|
| Enterprise | T1082 | 系统信息发现 | ||
| Enterprise | T1102 | .002 | 网络服务: Bidirectional Communication |
KARAE can use public cloud-based storage providers for command and control.[1] |
| Enterprise | T1105 | 输入工具传输 |
KARAE can upload and download files, including second-stage malware.[1] |
|