CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
During malware analysis, an incident responder determines that the attacker took a known Adobe Reader exploit and bundled it with a custom remote access trojan into a single malicious PDF file before ever sending it to the target. Which phase of the Cyber Kill Chain does this activity represent?
- AReconnaissance
- BInstallation
- CDelivery
- DWeaponization
Show answer & explanationAnswer & explanation
Correct answer: D. Weaponization
Weaponization is the Kill Chain phase in which an attacker couples an exploit with a payload (such as a trojan) into a deliverable artifact, occurring before the artifact is ever sent to a victim.
Why the other options are wrong
- A. Reconnaissance involves gathering information about the target, not building the malicious artifact.
- B. Installation refers to the malware establishing persistence after execution on the victim system.
- C. Delivery is the transmission of the weaponized artifact to the victim, which has not yet occurred.
Cyber Kill Chain: Weaponization
The stage where an attacker combines an exploit with a malicious payload to create a deliverable weapon (e.g., malicious document, executable).
- Occurs before Delivery
- Often produces a booby-trapped file (PDF, macro, executable)
- Second phase of Lockheed Martin's Cyber Kill Chain
Memory trick: Recon-Weaponize-Deliver-Exploit-Install-C2-Actions.