Terefos, A. (2020, November 18). TA505: A Brief History of Their Time. Retrieved July 14, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1140 Deobfuscate/Decode Files or Information |
GroupTA505 | TA505 has decrypted packed DLLs with an XOR key. |
| T1588.001 Malware |
GroupTA505 | TA505 has used malware such as Azorult and Cobalt Strike in their operations. |
| T1588.002 Tool |
GroupTA505 | TA505 has used a variety of tools in their operations, including AdFind, BloodHound, Mimikatz, and PowerSploit. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.