Financial Security Institute. (2020, February 28). Profiling of TA505 Threat Group That Continues to Attack the Financial Sector. Retrieved July 14, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareFlawedAmmyy | FlawedAmmyy has collected information and files from a compromised machine. |
| T1033 System Owner/User Discovery |
MalwareFlawedAmmyy | FlawedAmmyy enumerates the current user during the initial infection. |
| T1041 Exfiltration Over C2 Channel |
MalwareSDBbot | SDBbot has sent collected data from a compromised host to its C2 servers. |
| T1041 Exfiltration Over C2 Channel |
MalwareFlawedAmmyy | FlawedAmmyy has sent data collected from a compromised host to its C2 servers. |
| T1056 Input Capture |
MalwareFlawedAmmyy | FlawedAmmyy can collect mouse events. |
| T1056.001 Keylogging |
MalwareFlawedAmmyy | FlawedAmmyy can collect keyboard events. |
| T1057 Process Discovery |
MalwareSDBbot | SDBbot can enumerate a list of running processes on a compromised machine. |
| T1059.001 PowerShell |
MalwareFlawedAmmyy | FlawedAmmyy has used PowerShell to execute commands. |
| T1059.003 Windows Command Shell |
MalwareFlawedAmmyy | FlawedAmmyy has used `cmd` to execute commands on a compromised host. |
| T1069.001 Local Groups |
MalwareFlawedAmmyy | FlawedAmmyy enumerates the privilege level of the victim during the initial infection. |
| T1070.004 File Deletion |
MalwareFlawedAmmyy | FlawedAmmyy can execute batch scripts to delete files. |
| T1082 System Information Discovery |
MalwareAmadey | Amadey has collected the computer name and OS version from a compromised machine. |
| T1082 System Information Discovery |
MalwareSDBbot | SDBbot has the ability to identify the OS version, OS bit information and computer name. |
| T1083 File and Directory Discovery |
MalwareAmadey | Amadey has searched for folders associated with antivirus software. |
| T1105 Ingress Tool Transfer |
MalwareFlawedAmmyy | FlawedAmmyy can transfer files from C2. |
| T1106 Native API |
GroupTA505 | TA505 has deployed payloads that use Windows API calls on a compromised host. |
| T1112 Modify Registry |
GroupTA505 | TA505 has used malware to disable Windows Defender through modification of the Registry. |
| T1113 Screen Capture |
MalwareFlawedAmmyy | FlawedAmmyy can capture screenshots. |
| T1115 Clipboard Data |
MalwareFlawedAmmyy | FlawedAmmyy can collect clipboard data. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAmadey | Amadey has decoded antivirus name strings. |
| T1218.007 Msiexec |
MalwareFlawedAmmyy | FlawedAmmyy has been installed via `msiexec.exe`. |
| T1218.011 Rundll32 |
MalwareFlawedAmmyy | FlawedAmmyy has used `rundll32` for execution. |
| T1218.011 Rundll32 |
MalwareSDBbot | SDBbot has used rundll32.exe to execute DLLs. |
| T1518.001 Security Software Discovery |
MalwareAmadey | Amadey has checked for a variety of antivirus products. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAmadey | Amadey has changed the Startup folder to the one containing its executable by overwriting the registry keys. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFlawedAmmyy | FlawedAmmyy has established persistence via the `HKCU\SOFTWARE\microsoft\windows\currentversion\run` registry key. |
| T1553.005 Mark-of-the-Web Bypass |
MalwareAmadey | Amadey has modified the `:Zone.Identifier` in the ADS area to zero. |
| T1568.001 Fast Flux DNS |
MalwareAmadey | Amadey has used fast flux DNS for its C2. |
| T1583.001 Domains |
GroupTA505 | TA505 has registered domains to impersonate services such as Dropbox to distribute malware. |
| T1608.001 Upload Malware |
GroupTA505 | TA505 has staged malware on actor-controlled domains. |
| T1614 System Location Discovery |
MalwareSDBbot | SDBbot can collected the country code of a compromised machine. |
| T1685 Disable or Modify Tools |
GroupTA505 | TA505 has used malware to disable Windows Defender. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.