ATT&CKReferencesUnit 42 TA551 Jan 2021

Unit 42 TA551 Jan 2021

Duncan, B. (2021, January 7). TA551: Email Attack Campaign Switches from Valak to IcedID. Retrieved March 17, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1027.003
Steganography
GroupTA551

TA551 has hidden encoded data for malware DLLs in a PNG.

T1036
Masquerading
GroupTA551

TA551 has masked malware DLLs as dat and jpg files.

T1059.003
Windows Command Shell
GroupTA551

TA551 has used cmd.exe to execute commands.

T1105
Ingress Tool Transfer
GroupTA551

TA551 has retrieved DLLs and installer binaries for malware execution from C2.

T1204.002
Malicious File
GroupTA551

TA551 has prompted users to enable macros within spearphishing attachments to install malware.

T1218.005
Mshta
GroupTA551

TA551 has used mshta.exe to execute malicious payloads.

T1218.011
Rundll32
GroupTA551

TA551 has used rundll32.exe to load malicious DLLs.

T1566.001
Spearphishing Attachment
GroupTA551

TA551 has sent spearphishing attachments with password protected ZIP files.

T1568.002
Domain Generation Algorithms
GroupTA551

TA551 has used a DGA to generate URLs from executed macros.

T1589.002
Email Addresses
GroupTA551

TA551 has used spoofed company emails that were acquired from email clients on previously infected hosts to target other individuals.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.