Falcone, R. and Miller-Osborn, J.. (2016, January 24). Scarlet Mimic: Years-Long Espionage Campaign Targets Minority Activists. Retrieved February 10, 2016.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwareFakeM | FakeM C2 traffic attempts to evade detection by resembling data generated by legitimate messenger applications, such as MSN and Yahoo! messengers. Additionally, some variants of FakeM use modified SSL code for communications back to C2 servers, making SSL decryption ineffective. |
| T1005 Data from Local System |
MalwareMobileOrder | MobileOrder exfiltrates data collected from the victim mobile device. |
| T1036.002 Right-to-Left Override |
GroupScarlet Mimic | Scarlet Mimic has used the left-to-right override character in self-extracting RAR archive spearphishing attachment file names. |
| T1041 Exfiltration Over C2 Channel |
MalwarePsylo | Psylo exfiltrates data to its C2 server over the same protocol as C2 communications. |
| T1041 Exfiltration Over C2 Channel |
MalwareCallMe | CallMe exfiltrates data to its C2 server over the same protocol as C2 communications. |
| T1041 Exfiltration Over C2 Channel |
MalwareMobileOrder | MobileOrder exfiltrates data to its C2 server over the same protocol as C2 communications. |
| T1056.001 Keylogging |
MalwareFakeM | FakeM contains a keylogger module. |
| T1057 Process Discovery |
MalwareMobileOrder | MobileOrder has a command to upload information about all running processes to its C2 server. |
| T1059.004 Unix Shell |
MalwareCallMe | CallMe has the capability to create a reverse shell on victims. |
| T1070.006 Timestomp |
MalwarePsylo | Psylo has a command to conduct timestomping by setting a specified file’s timestamps to match those of a system file in the System32 directory. |
| T1071.001 Web Protocols |
MalwarePsylo | Psylo uses HTTPS for C2. |
| T1082 System Information Discovery |
MalwareMobileOrder | MobileOrder has a command to upload to its C2 server victim mobile device information, including IMEI, IMSI, SIM card serial number, phone number, Android version, and other information. |
| T1083 File and Directory Discovery |
MalwarePsylo | Psylo has commands to enumerate all storage devices and to find all files that start with a particular string. |
| T1083 File and Directory Discovery |
MalwareMobileOrder | MobileOrder has a command to upload to its C2 server information about files on the victim mobile device, including SD card size, installed app list, SMS content, contacts, and calling history. |
| T1095 Non-Application Layer Protocol |
MalwareFakeM | Some variants of FakeM use SSL to communicate with C2 servers. |
| T1105 Ingress Tool Transfer |
MalwareMobileOrder | MobileOrder has a command to download a file from the C2 server to the victim mobile device's SD card. |
| T1105 Ingress Tool Transfer |
MalwareCallMe | CallMe has the capability to download a file to the victim from the C2 server. |
| T1105 Ingress Tool Transfer |
MalwarePsylo | Psylo has a command to download a file to the system from its C2 server. |
| T1217 Browser Information Discovery |
MalwareMobileOrder | MobileOrder has a command to upload to its C2 server victim browser bookmarks. |
| T1573.001 Symmetric Cryptography |
MalwareFakeM | The original variant of FakeM encrypts C2 traffic using a custom encryption cipher that uses an XOR key of “YHCRA” and bit rotation between each XOR operation. Some variants of FakeM use RC4 to encrypt C2 traffic. |
| T1573.001 Symmetric Cryptography |
MalwareCallMe | CallMe uses AES to encrypt C2 traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.