Proofpoint Staff. (2018, June 8). TA505 shifts with the times. Retrieved May 28, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.005 Visual Basic |
GroupTA505 | TA505 has used VBS for code execution. |
| T1059.007 JavaScript |
GroupTA505 | TA505 has used JavaScript for code execution. |
| T1204.001 Malicious Link |
GroupTA505 | TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1204.002 Malicious File |
GroupTA505 | TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1559.002 Dynamic Data Exchange |
GroupTA505 | TA505 has leveraged malicious Word documents that abused DDE. |
| T1566.001 Spearphishing Attachment |
GroupTA505 | TA505 has used spearphishing emails with malicious attachments to initially compromise victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.