Marczak, B. and Scott-Railton, J.. (2016, May 29). Keep Calm and (Don’t) Enable Macros: A New Threat Actor Targets UAE Dissidents. Retrieved June 8, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupStealth Falcon | Stealth Falcon malware gathers data from the local victim system. |
| T1012 Query Registry |
GroupStealth Falcon | Stealth Falcon malware attempts to determine the installed version of .NET by querying the Registry. |
| T1016 System Network Configuration Discovery |
GroupStealth Falcon | Stealth Falcon malware gathers the Address Resolution Protocol (ARP) table from the victim. |
| T1033 System Owner/User Discovery |
GroupStealth Falcon | Stealth Falcon malware gathers the registered user and primary owner name via WMI. |
| T1041 Exfiltration Over C2 Channel |
GroupStealth Falcon | After data is collected by Stealth Falcon malware, it is exfiltrated over the existing C2 channel. |
| T1047 Windows Management Instrumentation |
GroupStealth Falcon | Stealth Falcon malware gathers system information via Windows Management Instrumentation (WMI). |
| T1053.005 Scheduled Task |
GroupStealth Falcon | Stealth Falcon malware creates a scheduled task entitled “IE Web Cache” to execute a malicious file hourly. |
| T1057 Process Discovery |
GroupStealth Falcon | Stealth Falcon malware gathers a list of running processes. |
| T1059 Command and Scripting Interpreter |
GroupStealth Falcon | Stealth Falcon malware uses WMI to script data collection and command execution on the victim. |
| T1059.001 PowerShell |
GroupStealth Falcon | Stealth Falcon malware uses PowerShell commands to perform various functions, including gathering system information via WMI and executing commands from its C2 server. |
| T1071.001 Web Protocols |
GroupStealth Falcon | Stealth Falcon malware communicates with its C2 server via HTTPS. |
| T1082 System Information Discovery |
GroupStealth Falcon | Stealth Falcon malware gathers system information via WMI, including the system directory, build number, serial number, version, manufacturer, model, and total physical memory. |
| T1555 Credentials from Password Stores |
GroupStealth Falcon | Stealth Falcon malware gathers passwords from multiple sources, including Windows Credential Vault and Outlook. |
| T1555.003 Credentials from Web Browsers |
GroupStealth Falcon | Stealth Falcon malware gathers passwords from multiple sources, including Internet Explorer, Firefox, and Chrome. |
| T1555.004 Windows Credential Manager |
GroupStealth Falcon | Stealth Falcon malware gathers passwords from the Windows Credential Vault. |
| T1573.001 Symmetric Cryptography |
GroupStealth Falcon | Stealth Falcon malware encrypts C2 traffic using RC4 with a hard-coded key. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.