MSRC. (2020, December 13). Customer Guidance on Recent Nation-State Cyber Attacks. Retrieved December 30, 2020.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1098.001 Additional Cloud Credentials |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 added credentials to OAuth Applications and Service Principals. |
| T1098.002 Additional Email Delegate Permissions |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 added their own devices as allowed IDs for active sync using `Set-CASMailbox`, allowing it to obtain copies of victim mailboxes. It also added additional permissions (such as Mail.Read and Mail.ReadWrite) to compromised Application or Service Principals. |
| T1218.011 Rundll32 |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `Rundll32.exe` to execute payloads. |
| T1606.002 SAML Tokens |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 created tokens using compromised SAML signing certificates. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.