Scott-Railton, J., et al. (2016, August 2). Group5: Syria and the Iranian Connection. Retrieved September 26, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
GroupGroup5 | Group5 disguised its malicious binaries with several layers of obfuscation, including encrypting the files. |
| T1056.001 Keylogging |
GroupGroup5 | Malware used by Group5 is capable of capturing keystrokes. |
| T1056.001 Keylogging |
MalwarenjRAT | njRAT is capable of logging keystrokes. |
| T1070.004 File Deletion |
GroupGroup5 | Malware used by Group5 is capable of remotely deleting files from victims. |
| T1113 Screen Capture |
GroupGroup5 | Malware used by Group5 is capable of watching the victim's screen. |
| T1125 Video Capture |
MalwarenjRAT | njRAT can access the victim's webcam. |
| T1555.003 Credentials from Web Browsers |
MalwarenjRAT | njRAT has a module that steals passwords saved in victim web browsers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.