MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity – MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupMagic Hound | Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz. |
| T1005 Data from Local System |
GroupCURIUM | CURIUM has exfiltrated data from a compromised machine. |
| T1027.010 Command Obfuscation |
GroupMagic Hound | Magic Hound has used base64-encoded commands. |
| T1027.013 Encrypted/Encoded File |
GroupMagic Hound | Magic Hound malware has used base64-encoded files and has also encrypted embedded strings with AES. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMagic Hound | Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink. |
| T1036.010 Masquerade Account Name |
GroupMagic Hound | Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines. |
| T1059.001 PowerShell |
GroupMagic Hound | Magic Hound has used PowerShell for execution and privilege escalation. |
| T1105 Ingress Tool Transfer |
GroupMagic Hound | Magic Hound has downloaded additional code and files from servers onto victims. |
| T1136.001 Local Account |
GroupMagic Hound | Magic Hound has created local accounts named `help` and `DefaultAccount` on compromised machines. |
| T1190 Exploit Public-Facing Application |
GroupMagic Hound | Magic Hound has exploited the Log4j utility (CVE-2021-44228), on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and Fortios SSL VPNs (CVE-2018-13379). |
| T1204.002 Malicious File |
GroupCURIUM | CURIUM has lured users into opening malicious files delivered via social media. |
| T1486 Data Encrypted for Impact |
GroupMagic Hound | Magic Hound has used BitLocker and DiskCryptor to encrypt targeted workstations. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMagic Hound | Magic Hound malware has used Registry Run keys to establish persistence. |
| T1566.002 Spearphishing Link |
GroupMagic Hound | Magic Hound has sent malicious URL links through email to victims. In some cases the URLs were shortened or linked to Word documents with malicious macros that executed PowerShells scripts to download Pupy. |
| T1566.003 Spearphishing via Service |
GroupCURIUM | CURIUM has used social media to deliver malicious files to victims. |
| T1585.001 Social Media Accounts |
GroupCURIUM | CURIUM has established a network of fictitious social media accounts, including on Facebook and LinkedIn, to establish relationships with victims, often posing as an attractive woman. |
| T1588.002 Tool |
GroupMagic Hound | Magic Hound has obtained and used tools like Havij, sqlmap, Metasploit, Mimikatz, and Plink. |
| T1589.001 Credentials |
GroupMagic Hound | Magic Hound gathered credentials from two victims that they then attempted to validate across 75 different websites. Magic Hound has also collected credentials from over 900 Fortinet VPN servers in the US, Europe, and Israel. |
| T1595.002 Vulnerability Scanning |
GroupMagic Hound | Magic Hound has conducted widespread scanning to identify public-facing systems vulnerable to CVE-2021-44228 in Log4j and ProxyShell vulnerabilities; CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in on-premises MS Exchange Servers; and CVE-2018-13379 in Fortinet FortiOS SSL VPNs. |
| T1598.003 Spearphishing Link |
GroupMagic Hound | Magic Hound has used SMS and email messages with links designed to steal credentials or track victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.