Burt, T. (2020, September 10). New cyberattacks targeting U.S. elections. Retrieved March 24, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1110 Brute Force |
GroupAPT28 | APT28 can perform brute force attacks to obtain credentials. |
| T1110.003 Password Spraying |
GroupAPT28 | APT28 has used a brute-force/password-spray tooling that operated in two modes: in password-spraying mode it conducted approximately four authentication attempts per hour per targeted account over the course of several days or weeks. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password spray attacks. |
| T1566.002 Spearphishing Link |
GroupZIRCONIUM | ZIRCONIUM has used malicious links in e-mails to deliver malware. |
| T1583.001 Domains |
GroupZIRCONIUM | ZIRCONIUM has purchased domains for use in targeted campaigns. |
| T1589.001 Credentials |
GroupAPT28 | APT28 has harvested user's login credentials. |
| T1598 Phishing for Information |
GroupAPT28 | APT28 has used spearphishing to compromise credentials. |
| T1598.003 Spearphishing Link |
GroupZIRCONIUM | ZIRCONIUM has used web beacons in e-mails to track hits to attacker-controlled URL's. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.