Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareQakBot | QakBot can use |
| T1047 Windows Management Instrumentation |
GroupCinnamon Tempest | Cinnamon Tempest has used Impacket for lateral movement via WMI. |
| T1059.003 Windows Command Shell |
GroupCinnamon Tempest | Cinnamon Tempest has executed ransomware using batch scripts deployed via GPO. |
| T1059.006 Python |
GroupCinnamon Tempest | Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files. |
| T1078.002 Domain Accounts |
GroupCinnamon Tempest | Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware. |
| T1078.003 Local Accounts |
GroupFIN7 | FIN7 has used compromised credentials for access as SYSTEM on Exchange servers. |
| T1080 Taint Shared Content |
GroupCinnamon Tempest | Cinnamon Tempest has deployed ransomware from a batch file in a network share. |
| T1082 System Information Discovery |
MalwareQakBot | QakBot can collect system information including the OS version and domain on a compromised host. |
| T1082 System Information Discovery |
GroupMustard Tempest | Mustard Tempest has used implants to perform system reconnaissance on targeted systems. |
| T1105 Ingress Tool Transfer |
GroupMustard Tempest | Mustard Tempest has deployed secondary payloads and third stage implants to compromised hosts. |
| T1190 Exploit Public-Facing Application |
GroupCinnamon Tempest | Cinnamon Tempest has exploited multiple unpatched vulnerabilities for initial access including vulnerabilities in Microsoft Exchange, Manage Engine AdSelfService Plus, Confluence, and Log4j. |
| T1190 Exploit Public-Facing Application |
GroupFIN7 | FIN7 has compromised targeted organizations through exploitation of CVE-2021-31207 in Exchange. |
| T1204.001 Malicious Link |
GroupMustard Tempest | Mustard Tempest has lured users into downloading malware through malicious links in fake advertisements and spearphishing emails. |
| T1204.002 Malicious File |
MalwareQakBot | QakBot has gained execution through users opening malicious attachments. |
| T1484.001 Group Policy Modification |
GroupCinnamon Tempest | Cinnamon Tempest has used Group Policy to deploy batch scripts for ransomware deployment. |
| T1566.001 Spearphishing Attachment |
MalwareQakBot | QakBot has spread through emails with malicious attachments. |
| T1574.001 DLL |
GroupCinnamon Tempest | Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons. Cinnamon Tempest has also abused legitimate executables to side-load weaponized DLLs. |
| T1583.008 Malvertising |
GroupMustard Tempest | Mustard Tempest has posted false advertisements including for software packages and browser updates in order to distribute malware. |
| T1608.006 SEO Poisoning |
GroupMustard Tempest | Mustard Tempest has poisoned search engine results to return fake software updates in order to distribute malware. |
| T1657 Financial Theft |
GroupCinnamon Tempest | Cinnamon Tempest has maintained leak sites for exfiltrated data in attempt to extort victims into paying a ransom. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.