Huss, D. (2016, March 1). Operation Transparent Tribe. Retrieved June 8, 2016.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareCrimson | Crimson can check the Registry for the presence of |
| T1016 System Network Configuration Discovery |
MalwareCrimson | Crimson contains a command to collect the victim MAC address and LAN IP. |
| T1020 Automated Exfiltration |
MalwarePeppy | Peppy has the ability to automatically exfiltrate files and keylogs. |
| T1025 Data from Removable Media |
MalwareCrimson | Crimson contains a module to collect data from removable drives. |
| T1027.013 Encrypted/Encoded File |
GroupTransparent Tribe | Transparent Tribe has dropped encoded executables on compromised hosts. |
| T1033 System Owner/User Discovery |
MalwareCrimson | Crimson can identify the user on a targeted system. |
| T1056.001 Keylogging |
MalwarePeppy | Peppy can log keystrokes on compromised hosts. |
| T1056.001 Keylogging |
MalwareCrimson | Crimson can use a module to perform keylogging on compromised hosts. |
| T1057 Process Discovery |
MalwareCrimson | Crimson contains a command to list processes. |
| T1059.003 Windows Command Shell |
MalwarePeppy | Peppy has the ability to execute shell commands. |
| T1059.005 Visual Basic |
GroupTransparent Tribe | Transparent Tribe has crafted VBS-based malicious documents. |
| T1070.004 File Deletion |
MalwareCrimson | Crimson has the ability to delete files from a compromised host. |
| T1071.001 Web Protocols |
MalwareCrimson | Crimson can use a HTTP GET request to download its final payload. |
| T1071.001 Web Protocols |
MalwarePeppy | Peppy can use HTTP to communicate with C2. |
| T1082 System Information Discovery |
MalwareCrimson | Crimson contains a command to collect the victim PC name and operating system. |
| T1083 File and Directory Discovery |
MalwarePeppy | Peppy can identify specific files for exfiltration. |
| T1083 File and Directory Discovery |
MalwareCrimson | Crimson contains commands to list files and directories, as well as search for files matching certain extensions from a defined list. |
| T1095 Non-Application Layer Protocol |
MalwareCrimson | Crimson uses a custom TCP protocol for C2. |
| T1105 Ingress Tool Transfer |
MalwareCrimson | Crimson contains a command to retrieve files from its C2 server. |
| T1105 Ingress Tool Transfer |
MalwarePeppy | Peppy can download and execute remote files. |
| T1112 Modify Registry |
MalwareCrimson | Crimson can set a Registry key to determine how long it has been installed and possibly to indicate the version number. |
| T1113 Screen Capture |
MalwarePeppy | Peppy can take screenshots on targeted systems. |
| T1113 Screen Capture |
MalwareCrimson | Crimson contains a command to perform screen captures. |
| T1114.001 Local Email Collection |
MalwareCrimson | Crimson contains a command to collect and exfiltrate emails from Outlook. |
| T1120 Peripheral Device Discovery |
MalwareCrimson | Crimson has the ability to discover pluggable/removable drives to extract files from. |
| T1125 Video Capture |
MalwareCrimson | Crimson can capture webcam video on targeted systems. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCrimson | Crimson can decode its encoded PE file prior to execution. |
| T1189 Drive-by Compromise |
GroupTransparent Tribe | Transparent Tribe has used websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools. |
| T1203 Exploitation for Client Execution |
GroupTransparent Tribe | Transparent Tribe has crafted malicious files to exploit CVE-2012-0158 and CVE-2010-3333 for execution. |
| T1204.002 Malicious File |
GroupTransparent Tribe | Transparent Tribe has used weaponized documents in e-mail to compromise targeted systems. |
| T1497.003 Time Based Checks |
MalwareCrimson | Crimson can determine when it has been installed on a host for at least 15 days before downloading the final payload. |
| T1518.001 Security Software Discovery |
MalwareCrimson | Crimson contains a command to collect information about anti-virus software on the victim. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCrimson | Crimson can add Registry run keys for persistence. |
| T1555.003 Credentials from Web Browsers |
MalwareCrimson | Crimson contains a module to steal credentials from Web browsers on the victim machine. |
| T1566.001 Spearphishing Attachment |
GroupTransparent Tribe | Transparent Tribe has sent spearphishing e-mails with attachments to deliver malicious payloads. |
| T1568 Dynamic Resolution |
GroupTransparent Tribe | Transparent Tribe has used dynamic DNS services to set up C2. |
| T1583.001 Domains |
GroupTransparent Tribe | Transparent Tribe has registered domains to mimic file sharing, government, defense, and research websites for use in targeted campaigns. |
| T1584.001 Domains |
GroupTransparent Tribe | Transparent Tribe has compromised domains for use in targeted malicious campaigns. |
| T1608.004 Drive-by Target |
GroupTransparent Tribe | Transparent Tribe has set up websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools. |
| T1680 Local Storage Discovery |
MalwareCrimson | Crimson contains a command to collect disk drive information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.