Jansen, W . (2021, January 12). Abusing cloud services to fly under the radar. Retrieved September 12, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.003 NTDS |
GroupChimera | Chimera has gathered the SYSTEM registry and ntds.dit files from target systems. Chimera specifically has used the NtdsAudit tool to dump the password hashes of domain users via |
| T1007 System Service Discovery |
GroupChimera | Chimera has used |
| T1012 Query Registry |
GroupChimera | Chimera has queried Registry keys using |
| T1016 System Network Configuration Discovery |
GroupChimera | Chimera has used ipconfig, Ping, and |
| T1018 Remote System Discovery |
GroupChimera | Chimera has utilized various scans and queries to find domain controllers and remote services in the target environment. |
| T1021.002 SMB/Windows Admin Shares |
GroupChimera | Chimera has used Windows admin shares to move laterally. |
| T1021.006 Windows Remote Management |
GroupChimera | Chimera has used WinRM for lateral movement. |
| T1033 System Owner/User Discovery |
GroupChimera | Chimera has used the |
| T1039 Data from Network Shared Drive |
GroupChimera | Chimera has collected data of interest from network shares. |
| T1041 Exfiltration Over C2 Channel |
GroupChimera | Chimera has used Cobalt Strike C2 beacons for data exfiltration. |
| T1046 Network Service Discovery |
GroupChimera | Chimera has used the |
| T1047 Windows Management Instrumentation |
GroupChimera | Chimera has used WMIC to execute remote commands. |
| T1049 System Network Connections Discovery |
GroupChimera | Chimera has used |
| T1053.005 Scheduled Task |
GroupChimera | Chimera has used scheduled tasks to invoke Cobalt Strike including through batch script |
| T1057 Process Discovery |
GroupChimera | Chimera has used |
| T1059.001 PowerShell |
GroupChimera | Chimera has used PowerShell scripts to execute malicious payloads and the DSInternals PowerShell module to make use of Active Directory features. |
| T1059.003 Windows Command Shell |
GroupChimera | Chimera has used the Windows Command Shell and batch scripts for execution on compromised hosts. |
| T1069.001 Local Groups |
GroupChimera | Chimera has used |
| T1070.006 Timestomp |
GroupChimera | Chimera has used a Windows version of the Linux |
| T1071.001 Web Protocols |
GroupChimera | Chimera has used HTTPS for C2 communications. |
| T1071.004 DNS |
GroupChimera | Chimera has used Cobalt Strike to encapsulate C2 in DNS traffic. |
| T1074.001 Local Data Staging |
GroupChimera | Chimera has staged stolen data locally on compromised hosts. |
| T1074.002 Remote Data Staging |
GroupChimera | Chimera has staged stolen data on designated servers in the target environment. |
| T1078.002 Domain Accounts |
GroupChimera | Chimera has used compromised domain accounts to gain access to the target environment. |
| T1083 File and Directory Discovery |
GroupChimera | Chimera has utilized multiple commands to identify data of interest in file and directory listings. |
| T1087.001 Local Account |
GroupChimera | Chimera has used |
| T1087.002 Domain Account |
GroupChimera | Chimera has has used |
| T1110.003 Password Spraying |
GroupChimera | Chimera has used multiple password spraying attacks against victim's remote services to obtain valid user and administrator accounts. |
| T1110.004 Credential Stuffing |
GroupChimera | Chimera has used credential stuffing against victim's remote services to obtain valid accounts. |
| T1111 Multi-Factor Authentication Interception |
GroupChimera | Chimera has registered alternate phone numbers for compromised users to intercept 2FA codes sent via SMS. |
| T1114.001 Local Email Collection |
GroupChimera | Chimera has harvested data from victim's e-mail including through execution of |
| T1114.002 Remote Email Collection |
GroupChimera | Chimera has harvested data from remote mailboxes including through execution of |
| T1119 Automated Collection |
GroupChimera | Chimera has used custom DLLs for continuous retrieval of data from memory. |
| T1124 System Time Discovery |
GroupChimera | Chimera has used |
| T1133 External Remote Services |
GroupChimera | Chimera has used legitimate credentials to login to an external VPN, Citrix, SSH, and other remote services. |
| T1135 Network Share Discovery |
GroupChimera | Chimera has used |
| T1201 Password Policy Discovery |
GroupChimera | Chimera has used the NtdsAudit utility to collect information related to accounts and passwords. |
| T1213.002 Sharepoint |
GroupChimera | Chimera has collected documents from the victim's SharePoint. |
| T1217 Browser Information Discovery |
GroupChimera | Chimera has used |
| T1482 Domain Trust Discovery |
GroupChimera | Chimera has |
| T1550.002 Pass the Hash |
GroupChimera | Chimera has dumped password hashes for use in pass the hash authentication attacks. |
| T1560.001 Archive via Utility |
GroupChimera | Chimera has used gzip for Linux OS and a modified RAR software to archive data on Windows hosts. |
| T1567.002 Exfiltration to Cloud Storage |
GroupChimera | Chimera has exfiltrated stolen data to OneDrive accounts. |
| T1569.002 Service Execution |
GroupChimera | Chimera has used PsExec to deploy beacons on compromised systems. |
| T1570 Lateral Tool Transfer |
GroupChimera | Chimera has copied tools between compromised hosts using SMB. |
| T1572 Protocol Tunneling |
GroupChimera | Chimera has encapsulated Cobalt Strike's C2 protocol in DNS and HTTPS. |
| T1574.001 DLL |
GroupChimera | Chimera has used side loading to place malicious DLLs in memory. |
| T1588.002 Tool |
GroupChimera | Chimera has obtained and used tools such as BloodHound, Cobalt Strike, Mimikatz, and PsExec. |
| T1589.001 Credentials |
GroupChimera | Chimera has collected credentials for the target organization from previous breaches for use in brute force attacks. |
| T1680 Local Storage Discovery |
GroupChimera | Chimera has used `fsutil fsinfo drives`, `systeminfo`, and `vssadmin list shadows` for system information including shadow volumes and drive information. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.