ATT&CKReferencesFireEye APT33 Sept 2017

FireEye APT33 Sept 2017

O'Leary, J., et al. (2017, September 20). Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware. Retrieved February 15, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareTURNEDUP

TURNEDUP is capable of creating a reverse shell.

T1082
System Information Discovery
MalwareTURNEDUP

TURNEDUP is capable of gathering system information.

T1105
Ingress Tool Transfer
MalwareTURNEDUP

TURNEDUP is capable of downloading additional files.

T1113
Screen Capture
MalwareTURNEDUP

TURNEDUP is capable of taking screenshots.

T1204.001
Malicious Link
GroupAPT33

APT33 has lured users to click links to malicious HTML applications delivered via spearphishing emails.

T1566.002
Spearphishing Link
GroupAPT33

APT33 has sent spearphishing emails containing links to .hta files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.