ATT&CKReferencesAPT15 Intezer June 2018

APT15 Intezer June 2018

Rosenberg, J. (2018, June 14). MirageFox: APT15 Resurfaces With New Tools Based On Old Ones. Retrieved September 21, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareMirageFox

MirageFox can gather the username from the victim’s machine.

T1059.003
Windows Command Shell
MalwareMirageFox

MirageFox has the capability to execute commands using cmd.exe.

T1082
System Information Discovery
MalwareMirageFox

MirageFox can collect CPU and architecture information from the victim’s machine.

T1140
Deobfuscate/Decode Files or Information
MalwareMirageFox

MirageFox has a function for decrypting data containing C2 configuration information.

T1574.001
DLL
MalwareMirageFox

MirageFox is likely loaded via DLL hijacking into a legitimate McAfee binary.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.