ATT&CKReferencesGoogle TAG COLDRIVER January 2024

Google TAG COLDRIVER January 2024

Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1036.004
Masquerade Task or Service
MalwareSpica

Spica has created a scheduled task named `CalendarChecker` for persistence on compromised hosts.

T1053.005
Scheduled Task
MalwareSpica

Spica has created a scheduled task named `CalendarChecker` to establish persistence.

T1059.001
PowerShell
MalwareSpica

Spica can use an obfuscated PowerShell command to create a scheduled task for persistence.

T1083
File and Directory Discovery
MalwareSpica

Spica can list filesystem contents on targeted systems.

T1095
Non-Application Layer Protocol
MalwareSpica

Spica can use JSON over WebSockets for C2 communications.

T1105
Ingress Tool Transfer
MalwareSpica

Spica can upload and download files to and from compromised hosts.

T1140
Deobfuscate/Decode Files or Information
MalwareSpica

Upon execution Spica can decode an embedded .pdf and write it to the desktop as a decoy document.

T1204.002
Malicious File
GroupStar Blizzard

Star Blizzard has lured targets into opening malicious .pdf files to deliver malware.

T1539
Steal Web Session Cookie
MalwareSpica

Spica has the ability to steal cookies from Chrome, Firefox, Opera, and Edge browsers.

T1560
Archive Collected Data
MalwareSpica

Spica can archive collected documents for exfiltration.

T1566.001
Spearphishing Attachment
GroupStar Blizzard

Star Blizzard has sent emails with malicious .pdf files to spread malware.

T1585.002
Email Accounts
GroupStar Blizzard

Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target.

T1598.002
Spearphishing Attachment
GroupStar Blizzard

Star Blizzard has sent emails to establish rapport with targets eventually sending messages with attachments containing links to credential-stealing sites.

T1598.003
Spearphishing Link
GroupStar Blizzard

Star Blizzard has sent emails to establish rapport with targets eventually sending messages with links to credential-stealing sites.

T1608.001
Upload Malware
GroupStar Blizzard

Star Blizzard has uploaded malicious payloads to cloud storage sites.

T1684.001
Impersonation
GroupStar Blizzard

Star Blizzard has registered impersonation email accounts to spoof experts in a particular field or individuals and organizations affiliated with the intended target.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.