Faou, M., Tartare, M., Dupuy, T. (2021, March 10). Exchange servers under siege from at least 10 APT groups. Retrieved May 21, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
GroupTonto Team | Tonto Team has used PowerShell to download additional payloads. |
| T1105 Ingress Tool Transfer |
GroupTonto Team | Tonto Team has downloaded malicious DLLs which served as a ShadowPad loader. |
| T1505.003 Web Shell |
GroupTonto Team | Tonto Team has used a first stage web shell after compromising a vulnerable Exchange server. |
| T1574.001 DLL |
GroupTonto Team | Tonto Team abuses a legitimate and signed Microsoft executable to launch a malicious DLL. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.