Eng, E., Caselden, D.. (2015, June 23). Operation Clandestine Wolf – Adobe Flash Zero-Day in APT3 Phishing Campaign. Retrieved January 14, 2016.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareSHOTPUT | SHOTPUT is obscured using XOR encoding and appended to a valid GIF file. |
| T1027.002 Software Packing |
GroupAPT3 | APT3 has been known to pack their tools. |
| T1203 Exploitation for Client Execution |
GroupAPT3 | APT3 has exploited the Adobe Flash Player vulnerability CVE-2015-3113 and Internet Explorer vulnerability CVE-2014-1776. |
| T1204.001 Malicious Link |
GroupAPT3 | APT3 has lured victims into clicking malicious links delivered through spearphishing. |
| T1566.002 Spearphishing Link |
GroupAPT3 | APT3 has sent spearphishing emails containing malicious links. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.