ATT&CKReferencesProofpoint TA2541 February 2022

Proofpoint TA2541 February 2022

Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
GroupTA2541

TA2541 has used file names to mimic legitimate Windows files or system functionality.

T1047
Windows Management Instrumentation
GroupTA2541

TA2541 has used WMI to query targeted systems for security products.

T1053.005
Scheduled Task
GroupTA2541

TA2541 has used scheduled tasks to establish persistence for installed tools.

T1055
Process Injection
GroupTA2541

TA2541 has injected malicious code into legitimate .NET related processes including regsvcs.exe, msbuild.exe, and installutil.exe.

T1059.001
PowerShell
GroupTA2541

TA2541 has used PowerShell to download files and to inject into various Windows processes.

T1059.005
Visual Basic
GroupTA2541

TA2541 has used VBS files to execute or establish persistence for additional payloads, often using file names consistent with email themes or mimicking system functionality.

T1082
System Information Discovery
GroupTA2541

TA2541 has collected system information prior to downloading malware on the targeted host.

T1204.001
Malicious Link
GroupTA2541

TA2541 has used malicious links to cloud and web services to gain execution on victim machines.

T1204.002
Malicious File
GroupTA2541

TA2541 has used macro-enabled MS Word documents to lure victims into executing malicious payloads.

T1518.001
Security Software Discovery
GroupTA2541

TA2541 has used tools to search victim systems for security products such as antivirus and firewall software.

T1547.001
Registry Run Keys / Startup Folder
GroupTA2541

TA2541 has placed VBS files in the Startup folder and used Registry run keys to establish persistence for malicious payloads.

T1566.001
Spearphishing Attachment
GroupTA2541

TA2541 has sent phishing emails with malicious attachments for initial access including MS Word documents.

T1566.002
Spearphishing Link
GroupTA2541

TA2541 has used spearphishing e-mails with malicious links to deliver malware.

T1568
Dynamic Resolution
GroupTA2541

TA2541 has used dynamic DNS services for C2 infrastructure.

T1583.001
Domains
GroupTA2541

TA2541 has registered domains often containing the keywords “kimjoy,” “h0pe,” and “grace,” using domain registrars including Netdorm and No-IP DDNS, and hosting providers including xTom GmbH and Danilenko, Artyom.

T1583.006
Web Services
GroupTA2541

TA2541 has hosted malicious files on various platforms including Google Drive, OneDrive, Discord, PasteText, ShareText, and GitHub.

T1588.001
Malware
GroupTA2541

TA2541 has used multiple strains of malware available for purchase on criminal forums or in open-source repositories.

T1608.001
Upload Malware
GroupTA2541

TA2541 has uploaded malware to various platforms including Google Drive, Pastetext, Sharetext, and GitHub.

T1685
Disable or Modify Tools
GroupTA2541

TA2541 has attempted to disable built-in security protections such as Windows AMSI.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.