ATT&CKReferencesCertfa Charming Kitten January 2021

Certfa Charming Kitten January 2021

Certfa Labs. (2021, January 8). Charming Kitten’s Christmas Gift. Retrieved May 3, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1114
Email Collection
GroupMagic Hound

Magic Hound has compromised email credentials in order to steal sensitive data.

T1204.001
Malicious Link
GroupMagic Hound

Magic Hound has attempted to lure victims into opening malicious links embedded in emails.

T1566.002
Spearphishing Link
GroupMagic Hound

Magic Hound has sent malicious URL links through email to victims. In some cases the URLs were shortened or linked to Word documents with malicious macros that executed PowerShells scripts to download Pupy.

T1583.001
Domains
GroupMagic Hound

Magic Hound has registered fraudulent domains such as "mail-newyorker.com" and "news12.com.recover-session-service.site" to target specific victims with phishing attacks.

T1584.001
Domains
GroupMagic Hound

Magic Hound has used compromised domains to host links targeted to specific phishing victims.

T1598.003
Spearphishing Link
GroupMagic Hound

Magic Hound has used SMS and email messages with links designed to steal credentials or track victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.