ATT&CKReferencesDistrict Court of NY APT10 Indictment December 2018

District Court of NY APT10 Indictment December 2018

US District Court Southern District of New York. (2018, December 17). United States v. Zhu Hua Indictment. Retrieved December 17, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
GroupmenuPass

menuPass has used RDP connections to move across the victim network.

T1036.005
Match Legitimate Resource Name or Location
GroupmenuPass

menuPass has been seen changing malicious files to appear legitimate.

T1056.001
Keylogging
GroupmenuPass

menuPass has used key loggers to steal usernames and passwords.

T1070.004
File Deletion
GroupmenuPass

A menuPass macro deletes files after it has decoded and decompressed them.

T1078
Valid Accounts
GroupmenuPass

menuPass has used valid accounts including shared between Managed Service Providers and clients to move between the two environments.

T1105
Ingress Tool Transfer
GroupmenuPass

menuPass has installed updates and new malware on victims.

T1199
Trusted Relationship
GroupmenuPass

menuPass has used legitimate access granted to Managed Service Providers in order to access victims of interest.

T1204.002
Malicious File
GroupmenuPass

menuPass has attempted to get victims to open malicious files such as Windows Shortcuts (.lnk) and/or Microsoft Office documents, sent via email as part of spearphishing campaigns.

T1560
Archive Collected Data
GroupmenuPass

menuPass has encrypted files and information before exfiltration.

T1566.001
Spearphishing Attachment
GroupmenuPass

menuPass has sent malicious Office documents via email as part of spearphishing campaigns as well as executables disguised as documents.

T1568.001
Fast Flux DNS
GroupmenuPass

menuPass has used dynamic DNS service providers to host malicious domains.

T1583.001
Domains
GroupmenuPass

menuPass has registered malicious domains for use in intrusion campaigns.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.