ATT&CKReferencesSecureList Griffon May 2019

SecureList Griffon May 2019

Namestnikov, Y. and Aime, F. (2019, May 8). FIN7.5: the infamous cybercrime rig “FIN7” continues its activities. Retrieved October 11, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
MalwareGRIFFON

GRIFFON has used sctasks for persistence.

T1059.001
PowerShell
MalwareGRIFFON

GRIFFON has used PowerShell to execute the Meterpreter downloader TinyMet.

T1059.007
JavaScript
MalwareGRIFFON

GRIFFON is written in and executed as JavaScript.

T1069.002
Domain Groups
MalwareGRIFFON

GRIFFON has used a reconnaissance module that can be used to retrieve Windows domain membership information.

T1082
System Information Discovery
MalwareGRIFFON

GRIFFON has used a reconnaissance module that can be used to retrieve information about a victim's computer, including the resolution of the workstation .

T1113
Screen Capture
MalwareGRIFFON

GRIFFON has used a screenshot module that can be used to take a screenshot of the remote system.

T1124
System Time Discovery
MalwareGRIFFON

GRIFFON has used a reconnaissance module that can be used to retrieve the date and time of the system.

T1547.001
Registry Run Keys / Startup Folder
MalwareGRIFFON

GRIFFON has used a persistence module that stores the implant inside the Registry, which executes at logon.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.