ATT&CKGroupsElderwood

Elderwood

G0066

Threat group.View on attack.mitre.org

About this group

Elderwood is a suspected Chinese cyber espionage group that was reportedly responsible for the 2009 Google intrusion known as Operation Aurora. The group has targeted defense organizations, supply chain manufacturers, human rights and nongovernmental organizations (NGOs), and IT service providers.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1027.002
Software Packing

Elderwood has packed malware payloads before delivery to victims.

T1027.013
Encrypted/Encoded File

Elderwood has encrypted documents and malicious executables.

T1105
Ingress Tool Transfer

The Ritsol backdoor trojan used by Elderwood can download files onto a compromised host from a remote location.

T1189
Drive-by Compromise

Elderwood has delivered zero-day exploits and malware to victims by injecting malicious code into specific public Web pages visited by targets within a particular sector.

T1203
Exploitation for Client Execution

Elderwood has used exploitation of endpoint software, including Microsoft Internet Explorer Adobe Flash vulnerabilities, to gain execution. They have also used zero-day exploits.

T1204.001
Malicious Link

Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open links.

T1204.002
Malicious File

Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open attachments.

T1566.001
Spearphishing Attachment

Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing malicious attachments.

T1566.002
Spearphishing Link

Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing a link to malicious content hosted on an uncommon Web server.

Software9

Campaigns0

None recorded.

References3

  1. CSM Elderwood Sept 2012 Open source
    Clayton, M.. (2012, September 14). Stealing US business secrets: Experts ID two huge cyber 'gangs' in China. Retrieved February 15, 2018.
  2. Security Affairs Elderwood Sept 2012 Open source
    Paganini, P. (2012, September 9). Elderwood project, who is behind Op. Aurora and ongoing attacks?. Retrieved February 13, 2018.
  3. Symantec Elderwood Sept 2012 Open source
    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.