Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
GroupOilRig | OilRig has used Remote Desktop Protocol for lateral movement. The group has also used tunneling tools to tunnel RDP into the environment. |
| T1025 Data from Removable Media |
GroupOilRig | OilRig has used Wireshark’s usbcapcmd utility to capture USB traffic. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupOilRig | OilRig has named a downloaded copy of the Plink tunneling utility as \ProgramData\Adobe.exe. |
| T1041 Exfiltration Over C2 Channel |
MalwarePowerExchange | PowerExchange can exfiltrate files via its email C2 channel. |
| T1047 Windows Management Instrumentation |
GroupOilRig | OilRig has used WMI for execution. |
| T1056.001 Keylogging |
GroupOilRig | OilRig has employed keyloggers including KEYPUNCH and LONGWATCH. |
| T1057 Process Discovery |
GroupOilRig | OilRig has run |
| T1059.001 PowerShell |
MalwarePowerExchange | PowerExchange can use PowerShell to execute commands received from C2. |
| T1069.001 Local Groups |
GroupOilRig | OilRig has used |
| T1071.003 Mail Protocols |
MalwarePowerExchange | PowerExchange can receive and send back the results of executed C2 commands through email. |
| T1082 System Information Discovery |
GroupOilRig | OilRig has run |
| T1105 Ingress Tool Transfer |
MalwarePowerExchange | PowerExchange can decode Base64-encoded files and call `WriteAllBytes` to write the files to compromised hosts. |
| T1112 Modify Registry |
GroupOilRig | OilRig has used reg.exe to modify system configuration. |
| T1115 Clipboard Data |
GroupOilRig | OilRig has used infostealer tools to copy clipboard data. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePowerExchange | PowerExchange can decode and decrypt C2 commands received via email. |
| T1543.003 Windows Service |
GroupOilRig | OilRig has used a compromised Domain Controller to create a service on a remote host. |
| T1572 Protocol Tunneling |
GroupOilRig | OilRig has used the Plink utility and other tools to create tunnels to C2 servers. |
| T1588.002 Tool |
GroupOilRig | OilRig has made use of the publicly available tools including Plink and Mimikatz. |
| T1686.003 Windows Host Firewall |
GroupOilRig | OilRig has modified Windows firewall rules to enable remote access. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.