Symantec Security Response. (2014, June 30). Dragonfly: Cyberespionage Attacks Against Energy Suppliers. Retrieved April 8, 2016.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
MalwareTrojan.Karagany | Trojan.Karagany can dump passwords and save them into |
| T1016 System Network Configuration Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about the Internet adapter configuration. |
| T1027.002 Software Packing |
MalwareTrojan.Karagany | Trojan.Karagany samples sometimes use common binary packers such as UPX and Aspack on top of a custom Delphi binary packer. |
| T1033 System Owner/User Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects the current username from the victim. |
| T1055 Process Injection |
MalwareBackdoor.Oldrea | Backdoor.Oldrea injects itself into explorer.exe. |
| T1057 Process Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about running processes. |
| T1057 Process Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can use Tasklist to collect a list of running tasks. |
| T1070.004 File Deletion |
MalwareBackdoor.Oldrea | Backdoor.Oldrea contains a cleanup module that removes traces of itself from the victim. |
| T1074.001 Local Data Staging |
MalwareTrojan.Karagany | Trojan.Karagany can create directories to store plugin output and stage data for exfiltration. |
| T1082 System Information Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about the OS and computer name. |
| T1083 File and Directory Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about available drives, default browser, desktop file list, My Documents, Internet history, program files, and root of available drives. It also searches for ICS-related software files. |
| T1087.003 Email Account |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects address book information from Outlook. |
| T1105 Ingress Tool Transfer |
MalwareTrojan.Karagany | Trojan.Karagany can upload, download, and execute files on the victim. |
| T1113 Screen Capture |
MalwareTrojan.Karagany | Trojan.Karagany can take a desktop screenshot and save the file into |
| T1132.001 Standard Encoding |
MalwareBackdoor.Oldrea | Some Backdoor.Oldrea samples use standard Base64 + bzip2, and some use standard Base64 + reverse XOR + RSA-2048 to decrypt data received from C2 servers. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBackdoor.Oldrea | Backdoor.Oldrea adds Registry Run keys to achieve persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTrojan.Karagany | Trojan.Karagany can create a link to itself in the Startup folder to automatically start itself upon system restart. |
| T1555.003 Credentials from Web Browsers |
MalwareBackdoor.Oldrea | Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool. |
| T1560 Archive Collected Data |
MalwareBackdoor.Oldrea | Backdoor.Oldrea writes collected data to a temporary file in an encrypted form before exfiltration to a C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.