CTU. (2018, September 27). Cybercriminals Increasingly Trying to Ensnare the Big Financial Fish. Retrieved September 20, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareSpicyOmelette | SpicyOmelette has collected data and other information from a compromised host. |
| T1016 System Network Configuration Discovery |
MalwareSpicyOmelette | SpicyOmelette can identify the IP of a compromised system. |
| T1018 Remote System Discovery |
MalwareSpicyOmelette | SpicyOmelette can identify payment systems, payment gateways, and ATM systems in compromised environments. |
| T1059.007 JavaScript |
MalwareSpicyOmelette | SpicyOmelette has the ability to execute arbitrary JavaScript code on a compromised host. |
| T1082 System Information Discovery |
MalwareSpicyOmelette | SpicyOmelette can identify the system name of a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareSpicyOmelette | SpicyOmelette can download malicious files from threat actor controlled AWS URL's. |
| T1204.001 Malicious Link |
MalwareSpicyOmelette | SpicyOmelette has been executed through malicious links within spearphishing emails. |
| T1204.001 Malicious Link |
GroupCobalt Group | Cobalt Group has sent emails containing malicious links that require users to execute a file or macro to infect the victim machine. |
| T1518 Software Discovery |
MalwareSpicyOmelette | SpicyOmelette can enumerate running software on a targeted system. |
| T1518.001 Security Software Discovery |
MalwareSpicyOmelette | SpicyOmelette can check for the presence of 29 different antivirus tools. |
| T1553.002 Code Signing |
MalwareSpicyOmelette | SpicyOmelette has been signed with valid digital certificates. |
| T1566.002 Spearphishing Link |
MalwareSpicyOmelette | SpicyOmelette has been distributed via emails containing a malicious link that appears to be a PDF document. |
| T1566.002 Spearphishing Link |
GroupCobalt Group | Cobalt Group has sent emails with URLs pointing to malicious documents. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.