ATT&CKReferencesMicrosoft Targeting Elections September 2020

Microsoft Targeting Elections September 2020

Burt, T. (2020, September 10). New cyberattacks targeting U.S. elections. Retrieved March 24, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1110
Brute Force
GroupAPT28

APT28 can perform brute force attacks to obtain credentials.

T1110.003
Password Spraying
GroupAPT28

APT28 has used a brute-force/password-spray tooling that operated in two modes: in password-spraying mode it conducted approximately four authentication attempts per hour per targeted account over the course of several days or weeks. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password spray attacks.

T1566.002
Spearphishing Link
GroupZIRCONIUM

ZIRCONIUM has used malicious links in e-mails to deliver malware.

T1583.001
Domains
GroupZIRCONIUM

ZIRCONIUM has purchased domains for use in targeted campaigns.

T1589.001
Credentials
GroupAPT28

APT28 has harvested user's login credentials.

T1598
Phishing for Information
GroupAPT28

APT28 has used spearphishing to compromise credentials.

T1598.003
Spearphishing Link
GroupZIRCONIUM

ZIRCONIUM has used web beacons in e-mails to track hits to attacker-controlled URL's.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.