Kizhakkinan, D., et al. (2016, May 11). Threat Actor Leverages Windows Zero-day Exploit in Payment Card Data Attacks. Retrieved February 12, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwarePUNCHTRACK | PUNCHTRACK scrapes memory for properly formatted payment card data. |
| T1027 Obfuscated Files or Information |
MalwarePUNCHTRACK | PUNCHTRACK is loaded and executed by a highly obfuscated launcher. |
| T1068 Exploitation for Privilege Escalation |
GroupFIN8 | FIN8 has exploited the CVE-2016-0167 local vulnerability. |
| T1071.001 Web Protocols |
MalwarePUNCHBUGGY | PUNCHBUGGY enables remote interaction and can obtain additional code over HTTPS GET and POST requests. |
| T1105 Ingress Tool Transfer |
GroupFIN8 | FIN8 has used remote code execution to download subsequent payloads. |
| T1204.001 Malicious Link |
GroupFIN8 | FIN8 has used emails with malicious links to lure victims into installing malware. |
| T1204.002 Malicious File |
GroupFIN8 | FIN8 has used malicious e-mail attachments to lure victims into executing malware. |
| T1566.001 Spearphishing Attachment |
GroupFIN8 | FIN8 has distributed targeted emails containing Word documents with embedded malicious macros. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.