Ray, V. (2016, November 22). Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison Ivy. Retrieved November 9, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
GroupTropic Trooper | Tropic Trooper is capable of enumerating the running processes on the system using |
| T1140 Deobfuscate/Decode Files or Information |
GroupTropic Trooper | Tropic Trooper used shellcode with an XOR algorithm to decrypt a payload. Tropic Trooper also decrypted image files which contained a payload. |
| T1203 Exploitation for Client Execution |
GroupTropic Trooper | Tropic Trooper has executed commands through Microsoft security vulnerabilities, including CVE-2017-11882, CVE-2018-0802, and CVE-2012-0158. |
| T1221 Template Injection |
GroupTropic Trooper | Tropic Trooper delivered malicious documents with the XLSX extension, typically used by OpenXML documents, but the file itself was actually an OLE (XLS) document. |
| T1518.001 Security Software Discovery |
GroupTropic Trooper | Tropic Trooper can search for anti-virus software running on the system. |
| T1547.004 Winlogon Helper DLL |
GroupTropic Trooper | Tropic Trooper has created the Registry key |
| T1566.001 Spearphishing Attachment |
GroupTropic Trooper | Tropic Trooper sent spearphishing emails that contained malicious Microsoft Office and fake installer file attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.