ATT&CKReferencesSymantec Chafer Dec 2015

Symantec Chafer Dec 2015

Symantec Security Response. (2015, December 7). Iran-based attackers use back door threats to spy on Middle Eastern targets. Retrieved April 17, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareCadelspy

Cadelspy has the ability to identify open windows on the compromised host.

T1033
System Owner/User Discovery
GroupAPT39

APT39 used Remexi to collect usernames from the system.

T1056.001
Keylogging
MalwareCadelspy

Cadelspy has the ability to log keystrokes on the compromised host.

T1082
System Information Discovery
MalwareCadelspy

Cadelspy has the ability to discover information about the compromised host.

T1113
Screen Capture
MalwareCadelspy

Cadelspy has the ability to capture screenshots and webcam photos.

T1115
Clipboard Data
MalwareCadelspy

Cadelspy has the ability to steal data from the clipboard.

T1120
Peripheral Device Discovery
MalwareCadelspy

Cadelspy has the ability to steal information about printers and the documents sent to printers.

T1123
Audio Capture
MalwareCadelspy

Cadelspy has the ability to record audio from the compromised host.

T1560
Archive Collected Data
MalwareCadelspy

Cadelspy has the ability to compress stolen data into a .cab file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.