Stolyarov, V. (2022, March 17). Exposing initial access broker with ties to Conti. Retrieved August 18, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareBumblebee | Bumblebee has the ability to identify the user name. |
| T1041 Exfiltration Over C2 Channel |
MalwareBumblebee | Bumblebee can send collected data in JSON format to C2. |
| T1047 Windows Management Instrumentation |
MalwareBumblebee | Bumblebee can use WMI to gather system information and to spawn processes for code injection. |
| T1059.003 Windows Command Shell |
MalwareBumblebee | Bumblebee can use `cmd.exe` to drop and run files. |
| T1082 System Information Discovery |
MalwareBumblebee | Bumblebee can enumerate the OS version and domain on a targeted system. |
| T1102 Web Service |
GroupEXOTIC LILY | EXOTIC LILY has used file-sharing services including WeTransfer, TransferNow, and OneDrive to deliver payloads. |
| T1105 Ingress Tool Transfer |
MalwareBumblebee | Bumblebee can download and execute additional payloads including through the use of a `Dex` command. |
| T1203 Exploitation for Client Execution |
GroupEXOTIC LILY | EXOTIC LILY has used malicious documents containing exploits for CVE-2021-40444 affecting Microsoft MSHTML. |
| T1204.001 Malicious Link |
GroupEXOTIC LILY | EXOTIC LILY has used malicious links to lure users into executing malicious payloads. |
| T1204.002 Malicious File |
GroupEXOTIC LILY | EXOTIC LILY has gained execution through victims clicking on malicious LNK files contained within ISO files, which can execute hidden DLLs within the ISO. |
| T1566.001 Spearphishing Attachment |
GroupEXOTIC LILY | EXOTIC LILY conducted an e-mail thread-hijacking campaign with malicious ISO attachments. |
| T1566.002 Spearphishing Link |
GroupEXOTIC LILY | EXOTIC LILY has relied on victims to open malicious links in e-mails for execution. |
| T1566.003 Spearphishing via Service |
GroupEXOTIC LILY | EXOTIC LILY has used the e-mail notification features of legitimate file sharing services for spearphishing. |
| T1583.001 Domains |
GroupEXOTIC LILY | EXOTIC LILY has registered domains to spoof targeted organizations by changing the top-level domain (TLD) to “.us”, “.co” or “.biz”. |
| T1585.001 Social Media Accounts |
GroupEXOTIC LILY | EXOTIC LILY has established social media profiles to mimic employees of targeted companies. |
| T1585.002 Email Accounts |
GroupEXOTIC LILY | EXOTIC LILY has created e-mail accounts to spoof targeted organizations. |
| T1589.002 Email Addresses |
GroupEXOTIC LILY | EXOTIC LILY has gathered targeted individuals' e-mail addresses through open source research and website contact forms. |
| T1593.001 Social Media |
GroupEXOTIC LILY | EXOTIC LILY has copied data from social media sites to impersonate targeted individuals. |
| T1594 Search Victim-Owned Websites |
GroupEXOTIC LILY | EXOTIC LILY has used contact forms on victim websites to generate phishing e-mails. |
| T1597 Search Closed Sources |
GroupEXOTIC LILY | EXOTIC LILY has searched for information on targeted individuals on business databases including RocketReach and CrunchBase. |
| T1608.001 Upload Malware |
GroupEXOTIC LILY | EXOTIC LILY has uploaded malicious payloads to file-sharing services including TransferNow, TransferXL, WeTransfer, and OneDrive. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.