PwC Threat Intelligence. (2023, December 5). The Tortoise and The Malware. Retrieved November 20, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.004 Unix Shell |
MalwareSnappyTCP | SnappyTCP creates the reverse shell using a pthread spawning a bash shell. |
| T1059.004 Unix Shell |
GroupSea Turtle | Sea Turtle used shell scripts for post-exploitation execution in victim environments. |
| T1071.001 Web Protocols |
MalwareSnappyTCP | SnappyTCP connects to the command and control server via a TCP socket using HTTP. |
| T1095 Non-Application Layer Protocol |
MalwareSnappyTCP | SnappyTCP spawns a reverse TCP shell following an HTTP-based negotiation. |
| T1190 Exploit Public-Facing Application |
GroupSea Turtle | Sea Turtle gained access to victim environments by exploiting multiple known vulnerabilities over several campaigns. |
| T1203 Exploitation for Client Execution |
GroupSea Turtle | Sea Turtle has used exploits for vulnerabilities such as CVE-2021-44228, CVE-2021-21974, and CVE-2022-0847 to achieve client code execution. |
| T1505.003 Web Shell |
GroupSea Turtle | Sea Turtle deployed the SnappyTCP web shell during intrusion operations. |
| T1505.003 Web Shell |
MalwareSnappyTCP | SnappyTCP is a reverse TCP shell with command and control capabilities used for persistence purposes. |
| T1573.002 Asymmetric Cryptography |
MalwareSnappyTCP | SnappyTCP can use OpenSSL and TLS certificates to encrypt traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.