Threat group.View on attack.mitre.org
Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz. |
| T1005 Data from Local System |
Magic Hound has used a web shell to exfiltrate a ZIP file containing a dump of LSASS memory on a compromised machine. |
| T1016 System Network Configuration Discovery |
Magic Hound malware gathers the victim's local IP address, MAC address, and external IP address. |
| T1016.001 Internet Connection Discovery |
Magic Hound has conducted a network call out to a specific website as part of their initial discovery activity. |
| T1016.002 Wi-Fi Discovery |
Magic Hound has collected names and passwords of all Wi-Fi networks to which a device has previously connected. |
| T1018 Remote System Discovery |
Magic Hound has used Ping for discovery on targeted networks. |
| T1021.001 Remote Desktop Protocol |
Magic Hound has used Remote Desktop Services to copy tools on targeted systems. |
| T1027.010 Command Obfuscation |
Magic Hound has used base64-encoded commands. |
| T1027.013 Encrypted/Encoded File |
Magic Hound malware has used base64-encoded files and has also encrypted embedded strings with AES. |
| T1033 System Owner/User Discovery |
Magic Hound malware has obtained the victim username and sent it to the C2 server. |
| T1036.004 Masquerade Task or Service |
Magic Hound has named a malicious script CacheTask.bat to mimic a legitimate task. |
| T1036.005 Match Legitimate Resource Name or Location |
Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink. |
| T1036.010 Masquerade Account Name |
Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines. |
| T1046 Network Service Discovery |
Magic Hound has used KPortScan 3.0 to perform SMB, RDP, and LDAP scanning. |
| T1047 Windows Management Instrumentation |
Magic Hound has used a tool to run `cmd /c wmic computersystem get domain` for discovery. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.