ATT&CKReferencesCheck Point APT31 February 2021

Check Point APT31 February 2021

Itkin, E. and Cohen, I. (2021, February 22). The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day. Retrieved March 24, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1027.002
Software Packing
GroupZIRCONIUM

ZIRCONIUM has used multi-stage packers for exploit code.

T1068
Exploitation for Privilege Escalation
GroupZIRCONIUM

ZIRCONIUM has exploited CVE-2017-0005 for local privilege escalation.

T1140
Deobfuscate/Decode Files or Information
GroupZIRCONIUM

ZIRCONIUM has used the AES256 algorithm with a SHA1 derived key to decrypt exploit code.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.