Svajcer, V. (2018, July 31). Multiple Cobalt Personality Disorder. Retrieved September 5, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareMore_eggs | More_eggs has the capability to gather the IP address from the victim's machine. |
| T1027.010 Command Obfuscation |
GroupCobalt Group | Cobalt Group obfuscated several scriptlets and code used on the victim’s machine, including through use of XOR and RC4. |
| T1033 System Owner/User Discovery |
MalwareMore_eggs | More_eggs has the capability to gather the username from the victim's machine. |
| T1059.001 PowerShell |
GroupCobalt Group | Cobalt Group has used powershell.exe to download and execute scripts. |
| T1059.003 Windows Command Shell |
GroupCobalt Group | Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files. |
| T1059.005 Visual Basic |
GroupCobalt Group | Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution. |
| T1059.007 JavaScript |
GroupCobalt Group | Cobalt Group has executed JavaScript scriptlets on the victim's machine. |
| T1070.004 File Deletion |
GroupCobalt Group | Cobalt Group deleted the DLL dropper from the victim’s machine to cover their tracks. |
| T1070.004 File Deletion |
MalwareMore_eggs | More_eggs can remove itself from a system. |
| T1071.001 Web Protocols |
MalwareMore_eggs | More_eggs uses HTTPS for C2. |
| T1071.001 Web Protocols |
GroupCobalt Group | Cobalt Group has used HTTPS for C2. |
| T1071.004 DNS |
GroupCobalt Group | Cobalt Group has used DNS tunneling for C2. |
| T1082 System Information Discovery |
MalwareMore_eggs | More_eggs has the capability to gather the OS version and computer name. |
| T1105 Ingress Tool Transfer |
MalwareMore_eggs | More_eggs can download and launch additional payloads. |
| T1203 Exploitation for Client Execution |
GroupCobalt Group | Cobalt Group had exploited multiple vulnerabilities for execution, including Microsoft’s Equation Editor (CVE-2017-11882), an Internet Explorer vulnerability (CVE-2018-8174), CVE-2017-8570, CVE-2017-0199, and CVE-2017-8759. |
| T1204.001 Malicious Link |
GroupCobalt Group | Cobalt Group has sent emails containing malicious links that require users to execute a file or macro to infect the victim machine. |
| T1204.002 Malicious File |
GroupCobalt Group | Cobalt Group has sent emails containing malicious attachments that require users to execute a file or macro to infect the victim machine. |
| T1218.003 CMSTP |
GroupCobalt Group | Cobalt Group has used the command |
| T1218.010 Regsvr32 |
GroupCobalt Group | Cobalt Group has used regsvr32.exe to execute scripts. |
| T1220 XSL Script Processing |
GroupCobalt Group | Cobalt Group used msxsl.exe to bypass AppLocker and to invoke Jscript code from an XSL file. |
| T1518.001 Security Software Discovery |
MalwareMore_eggs | More_eggs can obtain information on installed anti-malware programs. |
| T1559.002 Dynamic Data Exchange |
GroupCobalt Group | Cobalt Group has sent malicious Word OLE compound documents to victims. |
| T1566.001 Spearphishing Attachment |
GroupCobalt Group | Cobalt Group has sent spearphishing emails with various attachment types to corporate and personal email accounts of victim organizations. Attachment types have included .rtf, .doc, .xls, archives containing LNK files, and password protected archives containing .exe and .scr executables. |
| T1566.002 Spearphishing Link |
GroupCobalt Group | Cobalt Group has sent emails with URLs pointing to malicious documents. |
| T1572 Protocol Tunneling |
GroupCobalt Group | Cobalt Group has used the Plink utility to create SSH tunnels. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.