Threat Hunter Team. (2023, April 20). Daggerfly: APT Actor Targets Telecoms Company in Africa. Retrieved July 25, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
MalwareMgBot | MgBot includes modules for dumping and capturing credentials from process memory. |
| T1003.002 Security Account Manager |
GroupDaggerfly | Daggerfly used Reg to dump the Security Account Manager (SAM) hive from victim machines for follow-on credential extraction. |
| T1012 Query Registry |
GroupDaggerfly | Daggerfly used Reg to dump the Security Account Manager (SAM), System, and Security Windows registry hives from victim machines. |
| T1018 Remote System Discovery |
MalwareMgBot | MgBot includes modules for performing ARP scans of local connected systems. |
| T1033 System Owner/User Discovery |
MalwareMgBot | MgBot includes modules for identifying local users and administrators on victim machines. |
| T1036.003 Rename Legitimate Utilities |
GroupDaggerfly | Daggerfly used a renamed version of rundll32.exe, such as "dbengin.exe" located in the `ProgramData\Microsoft\PlayReady` directory, to proxy malicious DLL execution. |
| T1046 Network Service Discovery |
MalwareMgBot | MgBot includes modules for performing HTTP and server service scans. |
| T1056.001 Keylogging |
MalwareMgBot | MgBot includes keylogger payloads focused on the QQ chat application. |
| T1057 Process Discovery |
MalwareMgBot | MgBot includes a module for establishing a process watchdog for itself, identifying if the MgBot process is still running. |
| T1059.001 PowerShell |
GroupDaggerfly | Daggerfly used PowerShell to download and execute remote-hosted files on victim systems. |
| T1087.001 Local Account |
MalwareMgBot | MgBot includes modules for identifying local administrator accounts on victim systems. |
| T1087.002 Domain Account |
MalwareMgBot | MgBot includes modules for collecting information on Active Directory domain accounts. |
| T1105 Ingress Tool Transfer |
GroupDaggerfly | Daggerfly has used PowerShell and BITSAdmin to retrieve follow-on payloads from external locations for execution on victim machines. |
| T1115 Clipboard Data |
MalwareMgBot | MgBot can capture clipboard data. |
| T1123 Audio Capture |
MalwareMgBot | MgBot can capture input and output audio streams from infected devices. |
| T1136.001 Local Account |
GroupDaggerfly | Daggerfly created a local account on victim machines to maintain access. |
| T1218.011 Rundll32 |
GroupDaggerfly | Daggerfly proxied execution of malicious DLLs through a renamed rundll32.exe binary. |
| T1482 Domain Trust Discovery |
MalwareMgBot | MgBot includes modules for collecting information on local domain users and permissions. |
| T1555 Credentials from Password Stores |
MalwareMgBot | MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software. |
| T1555.003 Credentials from Web Browsers |
MalwareMgBot | MgBot includes modules for stealing credentials from various browsers and applications, including Chrome, Opera, Firefox, Foxmail, QQBrowser, FileZilla, and WinSCP. |
| T1574.001 DLL |
GroupDaggerfly | Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. Daggerfly is also linked to multiple other instances of side-loading for initial loading activity. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.