VOOZH about

URL: https://attack.mitre.org/software/S0232/

⇱ HOMEFRY, Software S0232 | MITRE ATT&CK®


ATT&CKcon 7.0 is coming October 27-28, 2026. Learn more about ATT&CKcon 7.0 and submit your proposal.
  1. Home
  2. Software
  3. HOMEFRY

HOMEFRY

HOMEFRY is a 64-bit Windows password dumper/cracker that has previously been used in conjunction with other Leviathan backdoors. [1]

ID: S0232
Type: MALWARE
Platforms: Windows
Version: 1.2
Created: 18 April 2018
Last Modified: 11 April 2024
Enterprise Layer
download view 👁 Image

Techniques Used

Domain ID Name Use
Enterprise T1059 .003 Command and Scripting Interpreter: Windows Command Shell

HOMEFRY uses a command-line interface.[1]

Enterprise T1027 .013 Obfuscated Files or Information: Encrypted/Encoded File

Some strings in HOMEFRY are obfuscated with XOR x56.[1]

Enterprise T1003 OS Credential Dumping

HOMEFRY can perform credential dumping.[1]

Groups That Use This Software

ID Name References
G0065 Leviathan

[1]

References

×