ATT&CKReferencesSANS Windshift August 2018

SANS Windshift August 2018

Karim, T. (2018, August). TRAILS OF WINDSHIFT. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1036.001
Invalid Code Signature
GroupWindshift

Windshift has used revoked certificates to sign malware.

T1204.001
Malicious Link
GroupWindshift

Windshift has used links embedded in e-mails to lure victims into executing malicious code.

T1204.002
Malicious File
GroupWindshift

Windshift has used e-mail attachments to lure victims into executing malicious code.

T1566.001
Spearphishing Attachment
GroupWindshift

Windshift has sent spearphishing emails with attachment to harvest credentials and deliver malware.

T1566.002
Spearphishing Link
GroupWindshift

Windshift has sent spearphishing emails with links to harvest credentials and deliver malware.

T1566.003
Spearphishing via Service
GroupWindshift

Windshift has used fake personas on social media to engage and target victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.