Symantec Security Response. (2016, September 6). Buckeye cyberespionage group shifts gaze from US to Hong Kong. Retrieved September 26, 2016.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAPT3 | APT3 has used a tool to dump credentials by injecting itself into lsass.exe and triggering with the argument "dig." |
| T1012 Query Registry |
MalwareOSInfo | OSInfo queries the registry to look for information about Terminal Services. |
| T1016 System Network Configuration Discovery |
GroupAPT3 | A keylogging tool used by APT3 gathers network information from the victim, including the MAC address, IP address, WINS, DHCP server, and gateway. |
| T1016 System Network Configuration Discovery |
MalwareOSInfo | OSInfo discovers the current domain information. |
| T1018 Remote System Discovery |
MalwareOSInfo | OSInfo performs a connection test to discover remote systems in the network |
| T1018 Remote System Discovery |
GroupAPT3 | APT3 has a tool that can detect the existence of remote systems. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT3 | APT3 will copy files over to Windows Admin Shares (like ADMIN$) as part of lateral movement. |
| T1027 Obfuscated Files or Information |
GroupAPT3 | APT3 obfuscates files or information to help evade defensive measures. |
| T1049 System Network Connections Discovery |
GroupAPT3 | APT3 has a tool that can enumerate current network connections. |
| T1049 System Network Connections Discovery |
MalwareOSInfo | OSInfo enumerates the current network connections similar to |
| T1053.005 Scheduled Task |
MalwareRemoteCMD | RemoteCMD can execute commands remotely by creating a new schedule task on the remote system |
| T1056.001 Keylogging |
GroupAPT3 | APT3 has used a keylogging tool that records keystrokes in encrypted files. |
| T1059.003 Windows Command Shell |
GroupAPT3 | An APT3 downloader uses the Windows command |
| T1069 Permission Groups Discovery |
GroupAPT3 | APT3 has a tool that can enumerate the permissions associated with Windows groups. |
| T1069.001 Local Groups |
MalwareOSInfo | OSInfo has enumerated the local administrators group. |
| T1069.002 Domain Groups |
MalwareOSInfo | OSInfo specifically looks for Domain Admins and power users within the domain. |
| T1078.002 Domain Accounts |
GroupAPT3 | APT3 leverages valid accounts after gaining credentials for use within the victim domain. |
| T1082 System Information Discovery |
MalwareOSInfo | OSInfo discovers information about the infected machine. |
| T1082 System Information Discovery |
GroupAPT3 | APT3 has a tool that can obtain information about the local system. |
| T1087.001 Local Account |
GroupAPT3 | APT3 has used a tool that can obtain info about local and global group users, power users, and administrators. |
| T1087.001 Local Account |
MalwareOSInfo | OSInfo enumerates local and domain users |
| T1087.002 Domain Account |
MalwareOSInfo | OSInfo enumerates local and domain users |
| T1105 Ingress Tool Transfer |
MalwareRemoteCMD | RemoteCMD copies a file over to the remote system before execution. |
| T1135 Network Share Discovery |
MalwareOSInfo | OSInfo discovers shares on the network |
| T1552.001 Credentials In Files |
GroupAPT3 | APT3 has a tool that can locate credentials in files on the file system such as those from Firefox or Chrome. |
| T1555.003 Credentials from Web Browsers |
GroupAPT3 | APT3 has used tools to dump passwords from browsers. |
| T1569.002 Service Execution |
MalwareRemoteCMD | RemoteCMD can execute commands remotely by creating a new service on the remote system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.