Rozmann, O., et al. (2024, May 1). Uncharmed: Untangling Iran's APT42 Operations. Retrieved October 9, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareTAMECAT | TAMECAT has used Windows Management Instrumentation (WMI) to query anti-virus products. |
| T1047 Windows Management Instrumentation |
GroupAPT42 | APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products. |
| T1056 Input Capture |
GroupAPT42 | APT42 has used credential harvesting websites. |
| T1059 Command and Scripting Interpreter |
MalwareNICECURL | NICECURL has provided an arbitrary command execution interface. |
| T1059.001 PowerShell |
MalwareTAMECAT | TAMECAT has used PowerShell to download and run additional content. |
| T1059.003 Windows Command Shell |
MalwareTAMECAT | TAMECAT has used `cmd.exe` to run the `curl` command. |
| T1059.005 Visual Basic |
MalwareTAMECAT | TAMECAT has used VBScript to query anti-virus products. |
| T1059.005 Visual Basic |
GroupAPT42 | APT42 has used a VBScript to query anti-virus products. |
| T1070 Indicator Removal |
GroupAPT42 | APT42 has cleared Chrome browser history. |
| T1070.004 File Deletion |
MalwareNICECURL | NICECURL has a function to remove artifacts. |
| T1071.001 Web Protocols |
MalwareTAMECAT | TAMECAT has used HTTP for C2 communications. |
| T1071.001 Web Protocols |
MalwareNICECURL | NICECURL has used HTTPS for C2 communications. |
| T1071.001 Web Protocols |
GroupAPT42 | APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. |
| T1102 Web Service |
GroupAPT42 | APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations. |
| T1105 Ingress Tool Transfer |
MalwareTAMECAT | TAMECAT has used `wget` and `curl` to download additional content. |
| T1105 Ingress Tool Transfer |
MalwareNICECURL | NICECURL has the ability to download additional content onto an infected machine, e.g. by using `curl`. |
| T1111 Multi-Factor Authentication Interception |
GroupAPT42 | APT42 has intercepted SMS-based one-time passwords and has set up two-factor authentication. Additionally, APT42 has used cloned or fake websites to capture MFA tokens. |
| T1132.001 Standard Encoding |
MalwareTAMECAT | TAMECAT has encoded C2 traffic with Base64. |
| T1132.001 Standard Encoding |
GroupAPT42 | APT42 has encoded C2 traffic with Base64. |
| T1518.001 Security Software Discovery |
MalwareTAMECAT | TAMECAT has used Windows Management Instrumentation (WMI) to check for anti-virus products. |
| T1518.001 Security Software Discovery |
GroupAPT42 | APT42 has used Windows Management Instrumentation (WMI) to check for anti-virus products. |
| T1530 Data from Cloud Storage |
GroupAPT42 | APT42 has collected data from Microsoft 365 environments. |
| T1566.002 Spearphishing Link |
GroupAPT42 | APT42 has sent spearphishing emails containing malicious links. |
| T1573.001 Symmetric Cryptography |
MalwareTAMECAT | TAMECAT has used AES to encrypt C2 traffic. |
| T1573.002 Asymmetric Cryptography |
MalwareNICECURL | NICECURL has used HTTPS for C2 communications. |
| T1573.002 Asymmetric Cryptography |
GroupAPT42 | APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS. |
| T1583.003 Virtual Private Server |
GroupAPT42 | APT42 has used anonymized infrastructure and Virtual Private Servers (VPSs) to interact with the victim’s environment. |
| T1588.002 Tool |
GroupAPT42 | APT42 has used built-in features in the Microsoft 365 environment and publicly available tools to avoid detection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.