ATT&CKReferencesSecureworks GOLD KINGSWOOD September 2018

Secureworks GOLD KINGSWOOD September 2018

CTU. (2018, September 27). Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish. Retrieved September 20, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSpicyOmelette

SpicyOmelette has collected data and other information from a compromised host.

T1016
System Network Configuration Discovery
MalwareSpicyOmelette

SpicyOmelette can identify the IP of a compromised system.

T1018
Remote System Discovery
MalwareSpicyOmelette

SpicyOmelette can identify payment systems, payment gateways, and ATM systems in compromised environments.

T1059.007
JavaScript
MalwareSpicyOmelette

SpicyOmelette has the ability to execute arbitrary JavaScript code on a compromised host.

T1082
System Information Discovery
MalwareSpicyOmelette

SpicyOmelette can identify the system name of a compromised host.

T1105
Ingress Tool Transfer
MalwareSpicyOmelette

SpicyOmelette can download malicious files from threat actor controlled AWS URL's.

T1204.001
Malicious Link
MalwareSpicyOmelette

SpicyOmelette has been executed through malicious links within spearphishing emails.

T1204.001
Malicious Link
GroupCobalt Group

Cobalt Group has sent emails containing malicious links that require users to execute a file or macro to infect the victim machine.

T1518
Software Discovery
MalwareSpicyOmelette

SpicyOmelette can enumerate running software on a targeted system.

T1518.001
Security Software Discovery
MalwareSpicyOmelette

SpicyOmelette can check for the presence of 29 different antivirus tools.

T1553.002
Code Signing
MalwareSpicyOmelette

SpicyOmelette has been signed with valid digital certificates.

T1566.002
Spearphishing Link
MalwareSpicyOmelette

SpicyOmelette has been distributed via emails containing a malicious link that appears to be a PDF document.

T1566.002
Spearphishing Link
GroupCobalt Group

Cobalt Group has sent emails with URLs pointing to malicious documents.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.