Kaspersky Lab's Global Research and Analysis Team. (2016, February 9). Poseidon Group: a Targeted Attack Boutique specializing in global cyber-espionage. Retrieved March 16, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupPoseidon Group | Poseidon Group conducts credential dumping on victims, with a focus on obtaining credentials belonging to domain and database servers. |
| T1007 System Service Discovery |
GroupPoseidon Group | After compromising a victim, Poseidon Group discovers all running services. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPoseidon Group | Poseidon Group tools attempt to spoof anti-virus processes as a means of self-defense. |
| T1049 System Network Connections Discovery |
GroupPoseidon Group | Poseidon Group obtains and saves information about victim network interfaces and addresses. |
| T1057 Process Discovery |
GroupPoseidon Group | After compromising a victim, Poseidon Group lists all running processes. |
| T1059.001 PowerShell |
GroupPoseidon Group | The Poseidon Group's Information Gathering Tool (IGT) includes PowerShell components. |
| T1087.001 Local Account |
GroupPoseidon Group | Poseidon Group searches for administrator accounts on both the local victim machine and the network. |
| T1087.002 Domain Account |
GroupPoseidon Group | Poseidon Group searches for administrator accounts on both the local victim machine and the network. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.