Davis, S. and Caban, D. (2017, December 19). APT34 - New Targeted Attack in the Middle East. Retrieved December 20, 2017.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupOilRig | OilRig has used credential dumping tools such as Mimikatz to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.004 LSA Secrets |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.005 Cached Domain Credentials |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1021.001 Remote Desktop Protocol |
GroupOilRig | OilRig has used Remote Desktop Protocol for lateral movement. The group has also used tunneling tools to tunnel RDP into the environment. |
| T1046 Network Service Discovery |
GroupOilRig | OilRig has used the publicly available tool SoftPerfect Network Scanner as well as a custom tool called GOLDIRONY to conduct network scanning. |
| T1047 Windows Management Instrumentation |
GroupOilRig | OilRig has used WMI for execution. |
| T1056.001 Keylogging |
GroupOilRig | OilRig has employed keyloggers including KEYPUNCH and LONGWATCH. |
| T1059.003 Windows Command Shell |
MalwareSEASHARPEE | SEASHARPEE can execute commands on victims. |
| T1070.006 Timestomp |
MalwareSEASHARPEE | SEASHARPEE can timestomp files on victims using a Web shell. |
| T1071.001 Web Protocols |
MalwarePOWRUNER | POWRUNER can use HTTP for C2 communications. |
| T1071.001 Web Protocols |
GroupOilRig | OilRig has used HTTP for C2. |
| T1071.004 DNS |
MalwarePOWRUNER | POWRUNER can use DNS for C2 communications. |
| T1071.004 DNS |
GroupOilRig | OilRig has used DNS for C2 including the publicly available |
| T1078 Valid Accounts |
GroupOilRig | OilRig has used compromised credentials to access other systems on a victim network. |
| T1105 Ingress Tool Transfer |
MalwareSEASHARPEE | SEASHARPEE can download remote files onto victims. |
| T1110 Brute Force |
GroupOilRig | OilRig has used brute force techniques to obtain credentials. |
| T1113 Screen Capture |
GroupOilRig | OilRig has a tool called CANDYKING to capture a screenshot of user's desktop. |
| T1133 External Remote Services |
GroupOilRig | OilRig uses remote services such as VPN, Citrix, or OWA to persist in an environment. |
| T1505.003 Web Shell |
GroupOilRig | OilRig has used web shells, often to maintain access to a victim network. |
| T1505.003 Web Shell |
MalwareSEASHARPEE | SEASHARPEE is a Web shell. |
| T1552.001 Credentials In Files |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1555 Credentials from Password Stores |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1555.003 Credentials from Web Browsers |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers. |
| T1572 Protocol Tunneling |
GroupOilRig | OilRig has used the Plink utility and other tools to create tunnels to C2 servers. |
| T1573.002 Asymmetric Cryptography |
GroupOilRig | OilRig used the PowerExchange utility and other tools to create tunnels to C2 servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.