ATT&CKReferencesProofpoint TA459 April 2017

Proofpoint TA459 April 2017

Axel F. (2017, April 27). APT Targets Financial Analysts with CVE-2017-0199. Retrieved February 15, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1001.002
Steganography
MalwareZeroT

ZeroT has retrieved stage 2 payloads as Bitmap images that use Least Significant Bit (LSB) steganography.

T1059.001
PowerShell
GroupTA459

TA459 has used PowerShell for execution of a payload.

T1059.005
Visual Basic
GroupTA459

TA459 has a VBScript for execution.

T1071.001
Web Protocols
MalwareZeroT

ZeroT has used HTTP for C2.

T1203
Exploitation for Client Execution
GroupTA459

TA459 has exploited Microsoft Word vulnerability CVE-2017-0199 for execution.

T1204.002
Malicious File
GroupTA459

TA459 has attempted to get victims to open malicious Microsoft Word attachment sent via spearphishing.

T1566.001
Spearphishing Attachment
GroupTA459

TA459 has targeted victims using spearphishing emails with malicious Microsoft Word attachments.

T1573.001
Symmetric Cryptography
MalwareZeroT

ZeroT has used RC4 to encrypt C2 traffic.

T1574.001
DLL
MalwareZeroT

ZeroT has used DLL side-loading to load malicious payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.