Microsoft. (2022, June 2). Exposing POLONIUM activity and infrastructure targeting Israeli organizations. Retrieved July 1, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareCreepyDrive | CreepyDrive can upload files to C2 from victim machines. |
| T1016 System Network Configuration Discovery |
MalwareCreepySnail | CreepySnail can use `getmac` and `Get-NetIPAddress` to enumerate network settings. |
| T1033 System Owner/User Discovery |
MalwareCreepySnail | CreepySnail can execute `getUsername` on compromised systems. |
| T1041 Exfiltration Over C2 Channel |
MalwareCreepySnail | CreepySnail can connect to C2 for data exfiltration. |
| T1059.001 PowerShell |
MalwareCreepySnail | CreepySnail can use PowerShell for execution, including the cmdlets `Invoke-WebRequst` and `Invoke-Expression`. |
| T1059.001 PowerShell |
MalwareCreepyDrive | CreepyDrive can use Powershell for execution, including the cmdlets `Invoke-WebRequest` and `Invoke-Expression`. |
| T1071.001 Web Protocols |
MalwareCreepyDrive | CreepyDrive can use HTTPS for C2 using the Microsoft Graph API. |
| T1071.001 Web Protocols |
MalwareCreepySnail | CreepySnail can use HTTP for C2. |
| T1078 Valid Accounts |
GroupPOLONIUM | POLONIUM has used valid compromised credentials to gain access to victim environments. |
| T1078.002 Domain Accounts |
MalwareCreepySnail | CreepySnail can use stolen credentials to authenticate on target networks. |
| T1083 File and Directory Discovery |
MalwareCreepyDrive | CreepyDrive can specify the local file path to upload files from. |
| T1090 Proxy |
GroupPOLONIUM | POLONIUM has used the AirVPN service for operational activity. |
| T1090 Proxy |
GroupCopyKittens | CopyKittens has used the AirVPN service for operational activity. |
| T1102.002 Bidirectional Communication |
MalwareCreepyDrive | CreepyDrive can use OneDrive for C2. |
| T1102.002 Bidirectional Communication |
GroupHEXANE | HEXANE has used cloud services, including OneDrive, for C2. |
| T1102.002 Bidirectional Communication |
GroupPOLONIUM | POLONIUM has used OneDrive and DropBox for C2. |
| T1105 Ingress Tool Transfer |
MalwareCreepyDrive | CreepyDrive can download files to the compromised host. |
| T1132.001 Standard Encoding |
MalwareCreepySnail | CreepySnail can use Base64 to encode its C2 traffic. |
| T1199 Trusted Relationship |
GroupPOLONIUM | POLONIUM has used compromised credentials from an IT company to target downstream customers including a law firm and aviation company. |
| T1550.001 Application Access Token |
MalwareCreepyDrive | CreepyDrive can use legitimate OAuth refresh tokens to authenticate with OneDrive. |
| T1567.002 Exfiltration to Cloud Storage |
GroupHEXANE | HEXANE has used cloud services, including OneDrive, for data exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
GroupPOLONIUM | POLONIUM has exfiltrated stolen data to POLONIUM-owned OneDrive and Dropbox accounts. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareCreepyDrive | CreepyDrive can use cloud services including OneDrive for data exfiltration. |
| T1583.006 Web Services |
GroupPOLONIUM | POLONIUM has created and used legitimate Microsoft OneDrive accounts for their operations. |
| T1588.002 Tool |
GroupPOLONIUM | POLONIUM has obtained and used tools such as AirVPN and plink in their operations. |
| T1588.002 Tool |
GroupCopyKittens | CopyKittens has used Metasploit, Empire, and AirVPN for post-exploitation activities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.