Malhotra, A. et al. (2021, May 13). Transparent Tribe APT expands its Windows malware arsenal. Retrieved September 2, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1189 Drive-by Compromise |
GroupTransparent Tribe | Transparent Tribe has used websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools. |
| T1204.001 Malicious Link |
GroupTransparent Tribe | Transparent Tribe has directed users to open URLs hosting malicious content. |
| T1204.001 Malicious Link |
MalwareObliqueRAT | ObliqueRAT has gained execution on targeted systems through luring users to click on links to malicious URLs. |
| T1204.002 Malicious File |
GroupTransparent Tribe | Transparent Tribe has used weaponized documents in e-mail to compromise targeted systems. |
| T1566.001 Spearphishing Attachment |
GroupTransparent Tribe | Transparent Tribe has sent spearphishing e-mails with attachments to deliver malicious payloads. |
| T1566.002 Spearphishing Link |
GroupTransparent Tribe | Transparent Tribe has embedded links to malicious downloads in e-mails. |
| T1583.001 Domains |
GroupTransparent Tribe | Transparent Tribe has registered domains to mimic file sharing, government, defense, and research websites for use in targeted campaigns. |
| T1608.004 Drive-by Target |
GroupTransparent Tribe | Transparent Tribe has set up websites with malicious hyperlinks and iframes to infect targeted victims with Crimson, njRAT, and other malicious tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.