Threat group.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments. |
| T1003.002 Security Account Manager |
Agrius dumped the SAM file on victim machines to capture credentials. |
| T1005 Data from Local System |
Agrius gathered data from database and other critical servers in victim environments, then used wiping mechanisms as an anti-analysis and anti-forensics mechanism. |
| T1018 Remote System Discovery |
Agrius used the tool NBTscan to scan for remote, accessible hosts in victim environments. |
| T1021.001 Remote Desktop Protocol |
Agrius tunnels RDP traffic through deployed web shells to access victim environments via compromised accounts. Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments. |
| T1036 Masquerading |
Agrius used the Plink tool for tunneling and connections to remote machines, renaming it |
| T1041 Exfiltration Over C2 Channel |
Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers. |
| T1046 Network Service Discovery |
Agrius used the open-source port scanner |
| T1059.003 Windows Command Shell |
Agrius uses ASPXSpy web shells to enable follow-on command execution via |
| T1074.001 Local Data Staging |
Agrius has used the folder, |
| T1078.002 Domain Accounts |
Agrius attempted to acquire valid credentials for victim environments through various means to enable follow-on lateral movement. |
| T1110 Brute Force |
Agrius engaged in various brute forcing activities via SMB in victim environments. |
| T1110.003 Password Spraying |
Agrius engaged in password spraying via SMB in victim environments. |
| T1119 Automated Collection |
Agrius used a custom tool, |
| T1140 Deobfuscate/Decode Files or Information |
Agrius has deployed base64-encoded variants of ASPXSpy to evade detection. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.