Threat group.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.002 Software Packing |
TA505 has used UPX to obscure malicious code. |
| T1027.010 Command Obfuscation |
TA505 has used base64 encoded PowerShell commands. |
| T1027.013 Encrypted/Encoded File |
TA505 has password-protected malicious Word documents. |
| T1055.001 Dynamic-link Library Injection |
TA505 has been seen injecting a DLL into winword.exe. |
| T1059.001 PowerShell |
TA505 has used PowerShell to download and execute malware and reconnaissance scripts. |
| T1059.003 Windows Command Shell |
TA505 has executed commands using |
| T1059.005 Visual Basic |
TA505 has used VBS for code execution. |
| T1059.007 JavaScript |
TA505 has used JavaScript for code execution. |
| T1069 Permission Groups Discovery |
TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run |
| T1071.001 Web Protocols |
TA505 has used HTTP to communicate with C2 nodes. |
| T1078.002 Domain Accounts |
TA505 has used stolen domain admin accounts to compromise additional hosts. |
| T1087.003 Email Account |
TA505 has used the tool EmailStealer to steal and send lists of e-mail addresses to a remote server. |
| T1105 Ingress Tool Transfer |
TA505 has downloaded additional malware to execute on victim systems. |
| T1106 Native API |
TA505 has deployed payloads that use Windows API calls on a compromised host. |
| T1112 Modify Registry |
TA505 has used malware to disable Windows Defender through modification of the Registry. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.