Microsoft Threat Intelligence Center. (2022, February 4). ACTINIUM targets Ukrainian organizations. Retrieved February 18, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareQuietSieve | QuietSieve can collect files from a compromised host. |
| T1016.001 Internet Connection Discovery |
MalwareQuietSieve | QuietSieve can check C2 connectivity with a `ping` to 8.8.8.8 (Google public DNS). |
| T1021.005 VNC |
GroupGamaredon Group | Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts. |
| T1027.007 Dynamic API Resolution |
MalwarePteranodon | Pteranodon can use a dynamic Windows hashing algorithm to map API components. |
| T1027.010 Command Obfuscation |
MalwarePowerPunch | PowerPunch can use Base64-encoded scripts. |
| T1027.010 Command Obfuscation |
GroupGamaredon Group | Gamaredon Group has used obfuscated or encrypted scripts. |
| T1053.005 Scheduled Task |
GroupGamaredon Group | Gamaredon Group has created scheduled tasks to launch executables after a designated number of minutes have passed. |
| T1059.001 PowerShell |
MalwarePowerPunch | PowerPunch has the ability to execute through PowerShell. |
| T1059.001 PowerShell |
GroupGamaredon Group | Gamaredon Group has used obfuscated PowerShell scripts for staging. Additionally, (LinkById : G0047) has used PowerShell based tools later in its attack chain. Additionally, Gamaredon Group has used the PowerShell cmdlet `Get-Command` to download and execute the next stage payload. |
| T1059.005 Visual Basic |
GroupGamaredon Group | Gamaredon Group has embedded malicious macros in document templates, which executed VBScript. Gamaredon Group has also delivered Microsoft Outlook VBA projects with embedded macros. Additionally, Gamaredon Group has executed VBScript files using wscript.exe. |
| T1071.001 Web Protocols |
MalwareQuietSieve | QuietSieve can use HTTPS in C2 communications. |
| T1083 File and Directory Discovery |
MalwareQuietSieve | QuietSieve can search files on the target host by extension, including doc, docx, xls, rtf, odt, txt, jpg, pdf, rar, zip, and 7z. |
| T1105 Ingress Tool Transfer |
GroupGamaredon Group | Gamaredon Group has downloaded additional malware and tools onto a compromised host. For example, Gamaredon Group uses a backdoor script to retrieve and decode additional payloads once in victim environments. |
| T1105 Ingress Tool Transfer |
MalwarePowerPunch | PowerPunch can download payloads from adversary infrastructure. |
| T1105 Ingress Tool Transfer |
MalwareQuietSieve | QuietSieve can download and execute payloads on a target host. |
| T1106 Native API |
MalwarePteranodon | Pteranodon has used various API calls. |
| T1113 Screen Capture |
MalwareQuietSieve | QuietSieve has taken screenshots every five minutes and saved them to the user's local Application Data folder under `Temp\SymbolSourceSymbols\icons` or `Temp\ModeAuto\icons`. |
| T1120 Peripheral Device Discovery |
MalwareQuietSieve | QuietSieve can identify and search removable drives for specific file name extensions. |
| T1135 Network Share Discovery |
MalwareQuietSieve | QuietSieve can identify and search networked drives for specific file name extensions. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePteranodon | Pteranodon can decrypt encrypted data strings prior to using them. |
| T1204.002 Malicious File |
GroupGamaredon Group | Gamaredon Group has attempted to get users to click on Office attachments with malicious macros embedded. Gamaredon Group has also attempted to get users to click on thematically named files. |
| T1221 Template Injection |
GroupGamaredon Group | Gamaredon Group has used DOCX files to download malicious DOT document templates and has used RTF template injection to download malicious payloads. Gamaredon Group can also inject malicious macros or remote templates into documents already present on compromised systems. |
| T1480.001 Environmental Keying |
MalwarePowerPunch | PowerPunch can use the volume serial number from a target host to generate a unique XOR key for the next stage payload. |
| T1564.003 Hidden Window |
MalwareQuietSieve | QuietSieve has the ability to execute payloads in a hidden window. |
| T1566.001 Spearphishing Attachment |
GroupGamaredon Group | Gamaredon Group has delivered spearphishing emails with malicious attachments to targets. Additionally, Gamaredon Group has distributed malicious LNK files compressed in ZIP archives. |
| T1583.001 Domains |
GroupGamaredon Group | Gamaredon Group has registered multiple domains to facilitate payload staging and C2. |
| T1608.001 Upload Malware |
GroupGamaredon Group | Gamaredon Group has registered domains to stage payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.