Accenture iDefense Unit. (2019, March 5). Mudcarp's Focus on Submarine Technologies. Retrieved August 24, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareBADFLICK | BADFLICK has uploaded files from victims' machines. |
| T1016 System Network Configuration Discovery |
MalwareBADFLICK | BADFLICK has captured victim IP address details. |
| T1055.001 Dynamic-link Library Injection |
GroupLeviathan | Leviathan has utilized techniques like reflective DLL loading to write a DLL into memory and load a shell that provides backdoor access to the victim. |
| T1059.001 PowerShell |
GroupLeviathan | Leviathan has used PowerShell for execution. |
| T1078 Valid Accounts |
GroupLeviathan | Leviathan has obtained valid accounts to gain initial access. |
| T1082 System Information Discovery |
MalwareBADFLICK | BADFLICK has captured victim computer name, memory space, and CPU details. |
| T1083 File and Directory Discovery |
MalwareBADFLICK | BADFLICK has searched for files on the infected host. |
| T1105 Ingress Tool Transfer |
MalwareBADFLICK | BADFLICK has download files from its C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBADFLICK | BADFLICK can decode shellcode using a custom rotating XOR cipher. |
| T1203 Exploitation for Client Execution |
GroupLeviathan | Leviathan has exploited multiple Microsoft Office and .NET vulnerabilities for execution, including CVE-2017-0199, CVE-2017-8759, and CVE-2017-11882. |
| T1204.002 Malicious File |
MalwareBADFLICK | BADFLICK has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1497.003 Time Based Checks |
MalwareBADFLICK | BADFLICK has delayed communication to the actor-controlled IP address by 5 minutes. |
| T1559.002 Dynamic Data Exchange |
GroupLeviathan | Leviathan has utilized OLE as a method to insert malicious content inside various phishing documents. |
| T1560.002 Archive via Library |
MalwareBADFLICK | BADFLICK has compressed data using the aPLib compression library. |
| T1566.001 Spearphishing Attachment |
MalwareBADFLICK | BADFLICK has been distributed via spearphishing campaigns containing malicious Microsoft Word documents. |
| T1583.001 Domains |
GroupLeviathan | Leviathan has established domains that impersonate legitimate entities to use for targeting efforts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.