Singh, S. and Antil, S. (2020, October 27). APT-31 Leverages COVID-19 Vaccine Theme and Abuses Legitimate Online Services. Retrieved March 24, 2021.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
GroupZIRCONIUM | ZIRCONIUM has used a tool to query the Registry for proxy settings. |
| T1016 System Network Configuration Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to enumerate proxy settings in the target environment. |
| T1033 System Owner/User Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to capture the username on a compromised host in order to register it with C2. |
| T1036 Masquerading |
GroupZIRCONIUM | ZIRCONIUM has spoofed legitimate applications in phishing lures and changed file extensions to conceal installation of malware. |
| T1036.004 Masquerade Task or Service |
GroupZIRCONIUM | ZIRCONIUM has created a run key named |
| T1041 Exfiltration Over C2 Channel |
GroupZIRCONIUM | ZIRCONIUM has exfiltrated files via the Dropbox API C2. |
| T1059.003 Windows Command Shell |
GroupZIRCONIUM | ZIRCONIUM has used a tool to open a Windows Command Shell on a remote host. |
| T1059.006 Python |
GroupZIRCONIUM | ZIRCONIUM has used Python-based implants to interact with compromised hosts. |
| T1082 System Information Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to capture the processor architecture of a compromised host in order to register it with C2. |
| T1102.002 Bidirectional Communication |
GroupZIRCONIUM | ZIRCONIUM has used Dropbox for C2 allowing upload and download of files as well as execution of arbitrary commands. |
| T1105 Ingress Tool Transfer |
GroupZIRCONIUM | ZIRCONIUM has used tools to download malicious files to compromised hosts. |
| T1124 System Time Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to capture the time on a compromised host in order to register it with C2. |
| T1204.001 Malicious Link |
GroupZIRCONIUM | ZIRCONIUM has used malicious links in e-mails to lure victims into downloading malware. |
| T1218.007 Msiexec |
GroupZIRCONIUM | ZIRCONIUM has used the msiexec.exe command-line utility to download and execute malicious MSI files. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupZIRCONIUM | ZIRCONIUM has created a Registry Run key named |
| T1555.003 Credentials from Web Browsers |
GroupZIRCONIUM | ZIRCONIUM has used a tool to steal credentials from installed web browsers including Microsoft Internet Explorer and Google Chrome. |
| T1566.002 Spearphishing Link |
GroupZIRCONIUM | ZIRCONIUM has used malicious links in e-mails to deliver malware. |
| T1567.002 Exfiltration to Cloud Storage |
GroupZIRCONIUM | ZIRCONIUM has exfiltrated stolen data to Dropbox. |
| T1573.001 Symmetric Cryptography |
GroupZIRCONIUM | ZIRCONIUM has used AES encrypted communications in C2. |
| T1583.006 Web Services |
GroupZIRCONIUM | ZIRCONIUM has used GitHub to host malware linked in spearphishing e-mails. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.