ATT&CKReferencesProofpoint TA505 Sep 2017

Proofpoint TA505 Sep 2017

Proofpoint Staff. (2017, September 27). Threat Actor Profile: TA505, From Dridex to GlobeImposter. Retrieved May 28, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupTA505

TA505 has password-protected malicious Word documents.

T1059.001
PowerShell
GroupTA505

TA505 has used PowerShell to download and execute malware and reconnaissance scripts.

T1059.005
Visual Basic
GroupTA505

TA505 has used VBS for code execution.

T1059.007
JavaScript
GroupTA505

TA505 has used JavaScript for code execution.

T1204.001
Malicious Link
GroupTA505

TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1204.002
Malicious File
GroupTA505

TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1486
Data Encrypted for Impact
GroupTA505

TA505 has used a wide variety of ransomware, such as Clop, Locky, Jaff, Bart, Philadelphia, and GlobeImposter, to encrypt victim files and demand a ransom payment.

T1552.001
Credentials In Files
GroupTA505

TA505 has used malware to gather credentials from FTP clients and Outlook.

T1555.003
Credentials from Web Browsers
GroupTA505

TA505 has used malware to gather credentials from Internet Explorer.

T1566.001
Spearphishing Attachment
GroupTA505

TA505 has used spearphishing emails with malicious attachments to initially compromise victims.

T1566.002
Spearphishing Link
GroupTA505

TA505 has sent spearphishing emails containing malicious links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.