Threat group.View on attack.mitre.org
Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Inception used a file hunting plugin to collect .txt, .pdf, .xls or .doc files from the infected host. |
| T1027.013 Encrypted/Encoded File |
Inception has encrypted malware payloads dropped on victim machines with AES and RC4 encryption. |
| T1057 Process Discovery |
Inception has used a reconnaissance module to identify active processes and other associated loaded modules. |
| T1059.001 PowerShell |
Inception has used PowerShell to execute malicious commands and payloads. |
| T1059.005 Visual Basic |
Inception has used VBScript to execute malicious commands and payloads. |
| T1069.002 Domain Groups |
Inception has used specific malware modules to gather domain membership. |
| T1071.001 Web Protocols |
Inception has used HTTP, HTTPS, and WebDav in network communications. |
| T1082 System Information Discovery |
Inception has used a reconnaissance module to gather information about the operating system and hardware on the infected host. |
| T1083 File and Directory Discovery |
Inception used a file listing plugin to collect information about file and directories both on local and remote drives. |
| T1090.003 Multi-hop Proxy |
Inception used chains of compromised routers to proxy C2 communications between them and cloud service providers. |
| T1102 Web Service |
Inception has incorporated at least five different cloud service providers into their C2 infrastructure including CloudMe. |
| T1203 Exploitation for Client Execution |
Inception has exploited CVE-2012-0158, CVE-2014-1761, CVE-2017-11882 and CVE-2018-0802 for execution. |
| T1204.002 Malicious File |
Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware. |
| T1218.005 Mshta |
Inception has used malicious HTA files to drop and execute malware. |
| T1218.010 Regsvr32 |
Inception has ensured persistence at system boot by setting the value |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.