Moran, N., et al. (2014, November 21). Operation Double Tap. Retrieved January 14, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
GroupAPT3 | An APT3 downloader uses the Windows command |
| T1053.005 Scheduled Task |
GroupAPT3 | An APT3 downloader creates persistence by creating the following scheduled task: |
| T1059.001 PowerShell |
GroupAPT3 | APT3 has used PowerShell on victim systems to download and run payloads after exploitation. |
| T1059.003 Windows Command Shell |
GroupAPT3 | An APT3 downloader uses the Windows command |
| T1090.002 External Proxy |
GroupAPT3 | An APT3 downloader establishes SOCKS5 connections for its initial C2. |
| T1095 Non-Application Layer Protocol |
GroupAPT3 | An APT3 downloader establishes SOCKS5 connections for its initial C2. |
| T1104 Multi-Stage Channels |
GroupAPT3 | An APT3 downloader first establishes a SOCKS5 connection to 192.157.198[.]103 using TCP port 1913; once the server response is verified, it then requests a connection to 192.184.60[.]229 on TCP port 81. |
| T1543.003 Windows Service |
GroupAPT3 | APT3 has a tool that creates a new service for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT3 | APT3 places scripts in the startup folder for persistence. |
| T1564.003 Hidden Window |
GroupAPT3 | APT3 has been known to use |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.