ATT&CKReferencesDOJ Iran Indictments March 2018

DOJ Iran Indictments March 2018

DOJ. (2018, March 23). U.S. v. Rafatnejad et al . Retrieved February 3, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1078
Valid Accounts
GroupSilent Librarian

Silent Librarian has used compromised credentials to obtain unauthorized access to online accounts.

T1110.003
Password Spraying
GroupSilent Librarian

Silent Librarian has used collected lists of names and e-mail accounts to use in password spraying attacks against private sector targets.

T1114
Email Collection
GroupSilent Librarian

Silent Librarian has exfiltrated entire mailboxes from compromised accounts.

T1114.003
Email Forwarding Rule
GroupSilent Librarian

Silent Librarian has set up auto forwarding rules on compromised e-mail accounts.

T1583.001
Domains
GroupSilent Librarian

Silent Librarian has acquired domains to establish credential harvesting pages, often spoofing the target organization and using free top level domains .TK, .ML, .GA, .CF, and .GQ.

T1585.002
Email Accounts
GroupSilent Librarian

Silent Librarian has established e-mail accounts to receive e-mails forwarded from compromised accounts.

T1589.002
Email Addresses
GroupSilent Librarian

Silent Librarian has collected e-mail addresses from targeted organizations from open Internet searches.

T1589.003
Employee Names
GroupSilent Librarian

Silent Librarian has collected lists of names for individuals from targeted organizations.

T1594
Search Victim-Owned Websites
GroupSilent Librarian

Silent Librarian has searched victim's websites to identify the interests and academic areas of targeted individuals and to scrape source code, branding, and organizational contact information for phishing pages.

T1598.003
Spearphishing Link
GroupSilent Librarian

Silent Librarian has used links in e-mails to direct victims to credential harvesting websites designed to appear like the targeted organization's login page.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.