Accenture. (2021, November 9). Who are latest targets of cyber group Lyceum?. Retrieved June 16, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareShark | Shark can upload files to its C2. |
| T1012 Query Registry |
MalwareShark | Shark can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID. |
| T1012 Query Registry |
MalwareMilan | Milan can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID. |
| T1027.013 Encrypted/Encoded File |
MalwareShark | Shark can use encrypted and encoded files for C2 configuration. |
| T1053.005 Scheduled Task |
MalwareMilan | Milan can establish persistence on a targeted host with scheduled tasks. |
| T1059.003 Windows Command Shell |
MalwareShark | Shark has the ability to use `CMD` to execute commands. |
| T1071.001 Web Protocols |
MalwareShark | Shark has the ability to use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareMilan | Milan can use HTTPS for communication with C2. |
| T1071.004 DNS |
MalwareMilan | Milan has the ability to use DNS for C2 communications. |
| T1071.004 DNS |
MalwareShark | Shark can use DNS in C2 communications. |
| T1082 System Information Discovery |
MalwareShark | Shark can collect the GUID of a targeted machine. |
| T1082 System Information Discovery |
MalwareMilan | Milan can enumerate the targeted machine's name and GUID. |
| T1105 Ingress Tool Transfer |
MalwareShark | Shark can download additional files from its C2 via HTTP or DNS. |
| T1568.002 Domain Generation Algorithms |
MalwareMilan | Milan can use hardcoded domains as an input for domain generation algorithms. |
| T1568.002 Domain Generation Algorithms |
MalwareShark | Shark can send DNS C2 communications using a unique domain generation algorithm. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.