ATT&CKReferencesSecureworks GOLD SAHARA

Secureworks GOLD SAHARA

Secureworks. (n.d.). GOLD SAHARA. Retrieved February 20, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1078
Valid Accounts
GroupAkira

Akira uses valid account information to remotely access victim networks, such as VPN credentials.

T1133
External Remote Services
GroupAkira

Akira uses compromised VPN accounts for initial access to victim networks.

T1213.002
Sharepoint
GroupAkira

Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.

T1219
Remote Access Tools
GroupAkira

Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments.

T1531
Account Access Removal
GroupAkira

Akira deletes administrator accounts in victim networks prior to encryption.

T1560.001
Archive via Utility
GroupAkira

Akira uses utilities such as WinRAR to archive data prior to exfiltration.

T1567.002
Exfiltration to Cloud Storage
GroupAkira

Akira will exfiltrate victim data using applications such as Rclone.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.