ATT&CKReferencesFireEye APT35 2018

FireEye APT35 2018

Mandiant. (2018). Mandiant M-Trends 2018. Retrieved November 17, 2024.

Open the source

Techniques1

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupOilRig

OilRig has used credential dumping tools such as Mimikatz to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.001
LSASS Memory
GroupMagic Hound

Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz.

T1003.004
LSA Secrets
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.005
Cached Domain Credentials
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1059.001
PowerShell
GroupMagic Hound

Magic Hound has used PowerShell for execution and privilege escalation.

T1070.004
File Deletion
GroupMagic Hound

Magic Hound has deleted and overwrote files to cover tracks.

T1098.002
Additional Email Delegate Permissions
GroupMagic Hound

Magic Hound granted compromised email accounts read access to the email boxes of additional targeted accounts. The group then was able to authenticate to the intended victim's OWA (Outlook Web Access) portal and read hundreds of email communications for information on Middle East organizations.

T1114.001
Local Email Collection
GroupMagic Hound

Magic Hound has collected .PST archives.

T1552.001
Credentials In Files
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1555
Credentials from Password Stores
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1555.003
Credentials from Web Browsers
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers.

T1560.001
Archive via Utility
GroupMagic Hound

Magic Hound has used gzip to archive dumped LSASS process memory and RAR to stage and compress local folders.

T1588.002
Tool
GroupMagic Hound

Magic Hound has obtained and used tools like Havij, sqlmap, Metasploit, Mimikatz, and Plink.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.