Crypto Library

April 3, 2025 ยท View on GitHub

ID C0059
Objective(s) Cryptography
Related ATT&CK Techniques None
Version 2.0
Created 17 January 2021
Last Modified 5 December 2023

Crypto Library

Malware uses a crypto library.

Methods

NameIDDescription
API CallC0059.001Malware uses crypto API calls.
Static Public LibraryC0059.002A public crypto library is embedded in the code.

Use in Malware

NameDateMethodDescription
Snake2004C0059.001Snake uses API calls to interface with cryptographic libraries. [1]

Detection

Tool: capaMappingAPIs
linked against Crypto++Crypto Library (C0059)--
linked against wolfCryptCrypto Library (C0059)--
linked against OpenSSLCrypto Library (C0059)--
linked against PolarSSL/mbed TLSCrypto Library (C0059)--
linked against wolfSSLCrypto Library (C0059)--

References

[1] https://www.cybereason.com/blog/research/threat-analysis-report-snake-infostealer-malware