ATT&CKReferencesCitizen Lab Group5

Citizen Lab Group5

Scott-Railton, J., et al. (2016, August 2). Group5: Syria and the Iranian Connection. Retrieved September 26, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupGroup5

Group5 disguised its malicious binaries with several layers of obfuscation, including encrypting the files.

T1056.001
Keylogging
GroupGroup5

Malware used by Group5 is capable of capturing keystrokes.

T1056.001
Keylogging
MalwarenjRAT

njRAT is capable of logging keystrokes.

T1070.004
File Deletion
GroupGroup5

Malware used by Group5 is capable of remotely deleting files from victims.

T1113
Screen Capture
GroupGroup5

Malware used by Group5 is capable of watching the victim's screen.

T1125
Video Capture
MalwarenjRAT

njRAT can access the victim's webcam.

T1555.003
Credentials from Web Browsers
MalwarenjRAT

njRAT has a module that steals passwords saved in victim web browsers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.