ATT&CKReferencesESET Exchange Mar 2021

ESET Exchange Mar 2021

Faou, M., Tartare, M., Dupuy, T. (2021, March 10). Exchange servers under siege from at least 10 APT groups. Retrieved May 21, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1059.001
PowerShell
GroupTonto Team

Tonto Team has used PowerShell to download additional payloads.

T1105
Ingress Tool Transfer
GroupTonto Team

Tonto Team has downloaded malicious DLLs which served as a ShadowPad loader.

T1505.003
Web Shell
GroupTonto Team

Tonto Team has used a first stage web shell after compromising a vulnerable Exchange server.

T1574.001
DLL
GroupTonto Team

Tonto Team abuses a legitimate and signed Microsoft executable to launch a malicious DLL.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.