Duncan, B. (2021, January 7). TA551: Email Attack Campaign Switches from Valak to IcedID. Retrieved March 17, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.003 Steganography |
GroupTA551 | TA551 has hidden encoded data for malware DLLs in a PNG. |
| T1036 Masquerading |
GroupTA551 | TA551 has masked malware DLLs as dat and jpg files. |
| T1059.003 Windows Command Shell |
GroupTA551 | TA551 has used |
| T1105 Ingress Tool Transfer |
GroupTA551 | TA551 has retrieved DLLs and installer binaries for malware execution from C2. |
| T1204.002 Malicious File |
GroupTA551 | TA551 has prompted users to enable macros within spearphishing attachments to install malware. |
| T1218.005 Mshta |
GroupTA551 | TA551 has used mshta.exe to execute malicious payloads. |
| T1218.011 Rundll32 |
GroupTA551 | TA551 has used rundll32.exe to load malicious DLLs. |
| T1566.001 Spearphishing Attachment |
GroupTA551 | TA551 has sent spearphishing attachments with password protected ZIP files. |
| T1568.002 Domain Generation Algorithms |
GroupTA551 | TA551 has used a DGA to generate URLs from executed macros. |
| T1589.002 Email Addresses |
GroupTA551 | TA551 has used spoofed company emails that were acquired from email clients on previously infected hosts to target other individuals. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.