Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1078 Valid Accounts |
GroupFIN5 | FIN5 has used legitimate VPN, RDP, Citrix, or VNC credentials to maintain access to a victim environment. |
| T1110 Brute Force |
GroupFIN5 | FIN5 has has used the tool GET2 Penetrator to look for remote login and hard-coded credentials. |
| T1133 External Remote Services |
GroupFIN5 | FIN5 has used legitimate VPN, Citrix, or VNC credentials to maintain access to a victim environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.