Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.004 Masquerade Task or Service |
MalwareSpica | Spica has created a scheduled task named `CalendarChecker` for persistence on compromised hosts. |
| T1053.005 Scheduled Task |
MalwareSpica | Spica has created a scheduled task named `CalendarChecker` to establish persistence. |
| T1059.001 PowerShell |
MalwareSpica | Spica can use an obfuscated PowerShell command to create a scheduled task for persistence. |
| T1083 File and Directory Discovery |
MalwareSpica | Spica can list filesystem contents on targeted systems. |
| T1095 Non-Application Layer Protocol |
MalwareSpica | Spica can use JSON over WebSockets for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareSpica | Spica can upload and download files to and from compromised hosts. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSpica | Upon execution Spica can decode an embedded .pdf and write it to the desktop as a decoy document. |
| T1204.002 Malicious File |
GroupStar Blizzard | Star Blizzard has lured targets into opening malicious .pdf files to deliver malware. |
| T1539 Steal Web Session Cookie |
MalwareSpica | Spica has the ability to steal cookies from Chrome, Firefox, Opera, and Edge browsers. |
| T1560 Archive Collected Data |
MalwareSpica | Spica can archive collected documents for exfiltration. |
| T1566.001 Spearphishing Attachment |
GroupStar Blizzard | Star Blizzard has sent emails with malicious .pdf files to spread malware. |
| T1585.002 Email Accounts |
GroupStar Blizzard | Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target. |
| T1598.002 Spearphishing Attachment |
GroupStar Blizzard | Star Blizzard has sent emails to establish rapport with targets eventually sending messages with attachments containing links to credential-stealing sites. |
| T1598.003 Spearphishing Link |
GroupStar Blizzard | Star Blizzard has sent emails to establish rapport with targets eventually sending messages with links to credential-stealing sites. |
| T1608.001 Upload Malware |
GroupStar Blizzard | Star Blizzard has uploaded malicious payloads to cloud storage sites. |
| T1684.001 Impersonation |
GroupStar Blizzard | Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.