CheckPoint. (2020, May 7). Naikon APT: Cyber Espionage Reloaded. Retrieved May 26, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
MalwareAria-body | Aria-body has the ability to identify the titles of running windows on a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareAria-body | Aria-body has the ability to identify the location, public IP address, and domain name on a compromised host. |
| T1025 Data from Removable Media |
MalwareAria-body | Aria-body has the ability to collect data from USB devices. |
| T1027.013 Encrypted/Encoded File |
MalwareAria-body | Aria-body has used an encrypted configuration file for its loader. |
| T1033 System Owner/User Discovery |
MalwareAria-body | Aria-body has the ability to identify the username on a compromised host. |
| T1049 System Network Connections Discovery |
MalwareAria-body | Aria-body has the ability to gather TCP and UDP table status listings. |
| T1055.001 Dynamic-link Library Injection |
MalwareAria-body | Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe. |
| T1057 Process Discovery |
MalwareAria-body | Aria-body has the ability to enumerate loaded modules for a process.. |
| T1070.004 File Deletion |
MalwareAria-body | Aria-body has the ability to delete files and directories on compromised hosts. |
| T1071.001 Web Protocols |
MalwareAria-body | Aria-body has used HTTP in C2 communications. |
| T1082 System Information Discovery |
MalwareAria-body | Aria-body has the ability to identify the hostname, computer name, Windows version, processor speed, and machine GUID on a compromised host. |
| T1083 File and Directory Discovery |
MalwareAria-body | Aria-body has the ability to gather metadata from a file and to search for file and directory names. |
| T1090 Proxy |
MalwareAria-body | Aria-body has the ability to use a reverse SOCKS proxy module. |
| T1095 Non-Application Layer Protocol |
MalwareAria-body | Aria-body has used TCP in C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareAria-body | Aria-body has the ability to download additional payloads from C2. |
| T1106 Native API |
MalwareAria-body | Aria-body has the ability to launch files using |
| T1113 Screen Capture |
MalwareAria-body | Aria-body has the ability to capture screenshots on compromised hosts. |
| T1134.001 Token Impersonation/Theft |
MalwareAria-body | Aria-body has the ability to duplicate a token from ntprint.exe. |
| T1134.002 Create Process with Token |
MalwareAria-body | Aria-body has the ability to execute a process using |
| T1137.006 Add-ins |
GroupNaikon | Naikon has used the RoyalRoad exploit builder to drop a second stage loader, intel.wll, into the Word Startup folder on the compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAria-body | Aria-body has the ability to decrypt the loader configuration and payload DLL. |
| T1204.002 Malicious File |
GroupNaikon | Naikon has convinced victims to open malicious attachments to execute malware. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAria-body | Aria-body has established persistence via the Startup folder or Run Registry key. |
| T1560 Archive Collected Data |
MalwareAria-body | Aria-body has used ZIP to compress data gathered on a compromised host. |
| T1566.001 Spearphishing Attachment |
GroupNaikon | Naikon has used malicious e-mail attachments to deliver malware. |
| T1568.002 Domain Generation Algorithms |
MalwareAria-body | Aria-body has the ability to use a DGA for C2 communications. |
| T1574.001 DLL |
GroupNaikon | Naikon has used DLL side-loading to load malicious DLL's into legitimate executables. |
| T1680 Local Storage Discovery |
MalwareAria-body | Aria-body has the ability to identify disk information on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.