ATT&CKReferencesSofacy DealersChoice

Sofacy DealersChoice

Falcone, R. (2018, March 15). Sofacy Uses DealersChoice to Target European Government Agency. Retrieved June 4, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareDealersChoice

DealersChoice makes modifications to open-source scripts from GitHub and executes them on the victim’s machine.

T1071.001
Web Protocols
MalwareDealersChoice

DealersChoice uses HTTP for communication with the C2 server.

T1203
Exploitation for Client Execution
MalwareDealersChoice

DealersChoice leverages vulnerable versions of Flash to perform execution.

T1566.001
Spearphishing Attachment
GroupAPT28

APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.