ATT&CKReferencesRSA Shell Crew

RSA Shell Crew

RSA Incident Response. (2014, January). RSA Incident Response Emerging Threat Profile: Shell Crew. Retrieved January 14, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1218.010
Regsvr32
GroupDeep Panda

Deep Panda has used regsvr32.exe to execute a server variant of Derusbi in victim networks.

T1546.008
Accessibility Features
GroupDeep Panda

Deep Panda has used the sticky-keys technique to bypass the RDP login screen on remote systems during intrusions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.