Moran 2014

Moran, N., Oppenheim, M., Engle, S., & Wartell, R.. (2014, September 3). Darwin’s Favorite APT Group [Blog]. Retrieved November 12, 2014.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareRIPTIDE

APT12 has used RIPTIDE, a RAT that uses HTTP to communicate.

T1203
Exploitation for Client Execution
GroupAPT12

APT12 has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities (CVE-2009-3129, CVE-2012-0158) and vulnerabilities in Adobe Reader and Flash (CVE-2009-4324, CVE-2009-0927, CVE-2011-0609, CVE-2011-0611).

T1204.002
Malicious File
GroupAPT12

APT12 has attempted to get victims to open malicious Microsoft Word and PDF attachment sent via spearphishing.

T1566.001
Spearphishing Attachment
GroupAPT12

APT12 has sent emails with malicious Microsoft Office documents and PDFs attached.

T1573.001
Symmetric Cryptography
MalwareRIPTIDE

APT12 has used the RIPTIDE RAT, which communicates over HTTP with a payload encrypted with RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.