ATT&CKReferencesKaspersky Poseidon Group

Kaspersky Poseidon Group

Kaspersky Lab's Global Research and Analysis Team. (2016, February 9). Poseidon Group: a Targeted Attack Boutique specializing in global cyber-espionage. Retrieved March 16, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupPoseidon Group

Poseidon Group conducts credential dumping on victims, with a focus on obtaining credentials belonging to domain and database servers.

T1007
System Service Discovery
GroupPoseidon Group

After compromising a victim, Poseidon Group discovers all running services.

T1036.005
Match Legitimate Resource Name or Location
GroupPoseidon Group

Poseidon Group tools attempt to spoof anti-virus processes as a means of self-defense.

T1049
System Network Connections Discovery
GroupPoseidon Group

Poseidon Group obtains and saves information about victim network interfaces and addresses.

T1057
Process Discovery
GroupPoseidon Group

After compromising a victim, Poseidon Group lists all running processes.

T1059.001
PowerShell
GroupPoseidon Group

The Poseidon Group's Information Gathering Tool (IGT) includes PowerShell components.

T1087.001
Local Account
GroupPoseidon Group

Poseidon Group searches for administrator accounts on both the local victim machine and the network.

T1087.002
Domain Account
GroupPoseidon Group

Poseidon Group searches for administrator accounts on both the local victim machine and the network.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.