Golovanov, S. (2018, December 6). DarkVishnya: Banks attacked through direct connection to local network. Retrieved May 15, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1040 Network Sniffing |
GroupDarkVishnya | DarkVishnya used network sniffing to obtain login data. |
| T1046 Network Service Discovery |
GroupDarkVishnya | DarkVishnya performed port scanning to obtain the list of active services. |
| T1059.001 PowerShell |
GroupDarkVishnya | DarkVishnya used PowerShell to create shellcode loaders. |
| T1110 Brute Force |
GroupDarkVishnya | DarkVishnya used brute-force attack to obtain login data. |
| T1135 Network Share Discovery |
GroupDarkVishnya | DarkVishnya scanned the network for public shared folders. |
| T1200 Hardware Additions |
GroupDarkVishnya | DarkVishnya physically connected Bash Bunny, Raspberry Pi, netbooks, and inexpensive laptops to the target organization's environment to access the company’s local network. |
| T1219 Remote Access Tools |
GroupDarkVishnya | DarkVishnya used DameWare Mini Remote Control for lateral movement. |
| T1543.003 Windows Service |
GroupDarkVishnya | DarkVishnya created new services for shellcode loaders distribution. |
| T1571 Non-Standard Port |
GroupDarkVishnya | DarkVishnya used ports 5190 and 7900 for shellcode listeners, and 4444, 4445, 31337 for shellcode C2. |
| T1588.002 Tool |
GroupDarkVishnya | DarkVishnya has obtained and used tools such as Impacket, Winexe, and PsExec. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.