ClearSky Cyber Security and Trend Micro. (2017, July). Operation Wilted Tulip: Exposing a cyber espionage apparatus. Retrieved August 21, 2017.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1053.005 Scheduled Task |
MalwareMatryoshka | Matryoshka can establish persistence by adding a Scheduled Task named "Microsoft Boost Kernel Optimization". |
| T1056.001 Keylogging |
MalwareMatryoshka | Matryoshka is capable of keylogging. |
| T1059 Command and Scripting Interpreter |
MalwareMatryoshka | Matryoshka is capable of providing Meterpreter shell access. |
| T1059.001 PowerShell |
GroupCopyKittens | CopyKittens has used PowerShell Empire. |
| T1059.003 Windows Command Shell |
MalwareTDTESS | TDTESS provides a reverse shell on the victim. |
| T1070.004 File Deletion |
MalwareTDTESS | TDTESS creates then deletes log files during installation of itself as a service. |
| T1070.006 Timestomp |
MalwareTDTESS | After creating a new service for persistence, TDTESS sets the file creation time for the service to the creation time of the victim's legitimate svchost.exe file. |
| T1071.004 DNS |
MalwareMatryoshka | Matryoshka uses DNS for C2. |
| T1105 Ingress Tool Transfer |
MalwareTDTESS | TDTESS has a command to download and execute an additional file. |
| T1113 Screen Capture |
MalwareMatryoshka | Matryoshka is capable of performing screen captures. |
| T1218.011 Rundll32 |
GroupCopyKittens | CopyKittens uses rundll32 to load various tools on victims, including a lateral movement tool named Vminst, Cobalt Strike, and shellcode. |
| T1543.003 Windows Service |
MalwareTDTESS | If running as administrator, TDTESS installs itself as a new service named bmwappushservice to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMatryoshka | Matryoshka can establish persistence by adding Registry Run keys. |
| T1553.002 Code Signing |
GroupCopyKittens | CopyKittens digitally signed an executable with a stolen certificate from legitimate company AI Squared. |
| T1555 Credentials from Password Stores |
MalwareMatryoshka | Matryoshka is capable of stealing Outlook passwords. |
| T1560.001 Archive via Utility |
GroupCopyKittens | CopyKittens uses ZPP, a .NET console program, to compress files with ZIP. |
| T1564.003 Hidden Window |
GroupCopyKittens | CopyKittens has used |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.