ATT&CKReferencesSymantec Dragonfly Sept 2017

Symantec Dragonfly Sept 2017

Symantec Security Response. (2014, July 7). Dragonfly: Western energy sector targeted by sophisticated attack group. Retrieved September 9, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1059.001
PowerShell
GroupDragonfly

Dragonfly has used PowerShell scripts for execution.

T1113
Screen Capture
GroupDragonfly

Dragonfly has performed screen captures of victims, including by using a tool, scr.exe (which matched the hash of ScreenUtil).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.