Cycraft. (2020, April 15). APT Group Chimera - APT Operation Skeleton key Targets Taiwan Semiconductor Vendors. Retrieved August 24, 2020..
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.003 NTDS |
GroupChimera | Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via |
| T1021.001 Remote Desktop Protocol |
GroupChimera | Chimera has used RDP to access targeted systems. |
| T1021.002 SMB/Windows Admin Shares |
GroupChimera | Chimera has used Windows admin shares to move laterally. |
| T1027.010 Command Obfuscation |
GroupChimera | Chimera has encoded PowerShell commands. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupChimera | Chimera has renamed malware to GoogleUpdate.exe and WinRAR to jucheck.exe, RecordedTV.ms, teredo.tmp, update.exe, and msadcs1.exe. |
| T1047 Windows Management Instrumentation |
GroupChimera | Chimera has used WMIC to execute remote commands. |
| T1053.005 Scheduled Task |
GroupChimera | Chimera has used scheduled tasks to invoke Cobalt Strike including through batch script |
| T1059.001 PowerShell |
GroupChimera | Chimera has used PowerShell scripts to execute malicious payloads and the DSInternals PowerShell module to make use of Active Directory features. |
| T1070.004 File Deletion |
GroupChimera | Chimera has performed file deletion to evade detection. |
| T1078 Valid Accounts |
GroupChimera | Chimera has used a valid account to maintain persistence via scheduled task. |
| T1087.002 Domain Account |
GroupChimera | Chimera has has used |
| T1105 Ingress Tool Transfer |
GroupChimera | Chimera has remotely copied tools and malware onto targeted systems. |
| T1106 Native API |
GroupChimera | Chimera has used direct Windows system calls by leveraging Dumpert. |
| T1133 External Remote Services |
GroupChimera | Chimera has used legitimate credentials to login to an external VPN, Citrix, SSH, and other remote services. |
| T1556.001 Domain Controller Authentication |
GroupChimera | Chimera's malware has altered the NTLM authentication program on domain controllers to allow Chimera to login without a valid credential. |
| T1560.001 Archive via Utility |
GroupChimera | Chimera has used gzip for Linux OS and a modified RAR software to archive data on Windows hosts. |
| T1588.002 Tool |
GroupChimera | Chimera has obtained and used tools such as BloodHound, Cobalt Strike, Mimikatz, and PsExec. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.