| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1543 | .001 | 创建或修改系统进程: Launch Agent |
The Komplex trojan creates a persistent launch agent called with |
| Enterprise | T1573 | .001 | 加密通道: Symmetric Cryptography |
The Komplex C2 channel uses an 11-byte XOR algorithm to hide data.[2] |
| Enterprise | T1071 | .001 | 应用层协议: Web Protocols | |
| Enterprise | T1070 | .004 | 移除指标: File Deletion | |
| Enterprise | T1033 | 系统所有者/用户发现 |
The OsInfo function in Komplex collects the current running username.[2] |
|
| Enterprise | T1057 | 进程发现 |
The OsInfo function in Komplex collects a running process list.[2] |
|
| Enterprise | T1564 | .001 | 隐藏伪装: Hidden Files and Directories |
The Komplex payload is stored in a hidden directory at |