ATT&CKReferencesESET Nomadic Octopus 2018

ESET Nomadic Octopus 2018

Cherepanov, A. (2018, October 4). Nomadic Octopus Cyber espionage in Central Asia. Retrieved October 13, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareOctopus

Octopus can exfiltrate files from the system using a documents collector tool.

T1036.005
Match Legitimate Resource Name or Location
MalwareOctopus

Octopus has been disguised as legitimate programs, such as Java and Telegram Messenger.

T1059.001
PowerShell
GroupNomadic Octopus

Nomadic Octopus has used PowerShell for execution.

T1059.003
Windows Command Shell
GroupNomadic Octopus

Nomadic Octopus used cmd.exe /c within a malicious macro.

T1071.001
Web Protocols
MalwareOctopus

Octopus has used HTTP GET and POST requests for C2 communications.

T1074.001
Local Data Staging
MalwareOctopus

Octopus has stored collected information in the Application Data directory on a compromised host.

T1083
File and Directory Discovery
MalwareOctopus

Octopus can collect information on the Windows directory and searches for compressed RAR files on the host.

T1105
Ingress Tool Transfer
MalwareOctopus

Octopus can download additional files and tools onto the victim’s machine.

T1105
Ingress Tool Transfer
GroupNomadic Octopus

Nomadic Octopus has used malicious macros to download additional files to the victim's machine.

T1113
Screen Capture
MalwareOctopus

Octopus can capture screenshots of the victims’ machine.

T1204.002
Malicious File
GroupNomadic Octopus

Nomadic Octopus as attempted to lure victims into clicking on malicious attachments within spearphishing emails.

T1204.002
Malicious File
MalwareOctopus

Octopus has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1560.001
Archive via Utility
MalwareOctopus

Octopus has compressed data before exfiltrating it using a tool called Abbrevia.

T1564.003
Hidden Window
GroupNomadic Octopus

Nomadic Octopus executed PowerShell in a hidden window.

T1566.001
Spearphishing Attachment
MalwareOctopus

Octopus has been delivered via spearsphishing emails.

T1566.001
Spearphishing Attachment
GroupNomadic Octopus

Nomadic Octopus has targeted victims with spearphishing emails containing malicious attachments.

T1567.002
Exfiltration to Cloud Storage
MalwareOctopus

Octopus has exfiltrated data to file sharing sites.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.