ATT&CKReferencesTalos Transparent Tribe May 2021

Talos Transparent Tribe May 2021

Malhotra, A. et al. (2021, May 13). Transparent Tribe APT expands its Windows malware arsenal. Retrieved September 2, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1189
Drive-by Compromise
GroupTransparent Tribe

Transparent Tribe has used websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools.

T1204.001
Malicious Link
GroupTransparent Tribe

Transparent Tribe has directed users to open URLs hosting malicious content.

T1204.001
Malicious Link
MalwareObliqueRAT

ObliqueRAT has gained execution on targeted systems through luring users to click on links to malicious URLs.

T1204.002
Malicious File
GroupTransparent Tribe

Transparent Tribe has used weaponized documents in e-mail to compromise targeted systems.

T1566.001
Spearphishing Attachment
GroupTransparent Tribe

Transparent Tribe has sent spearphishing e-mails with attachments to deliver malicious payloads.

T1566.002
Spearphishing Link
GroupTransparent Tribe

Transparent Tribe has embedded links to malicious downloads in e-mails.

T1583.001
Domains
GroupTransparent Tribe

Transparent Tribe has registered domains to mimic file sharing, government, defense, and research websites for use in targeted campaigns.

T1608.004
Drive-by Target
GroupTransparent Tribe

Transparent Tribe has set up websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.