Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareHyperBro | HyperBro can list all services and their configurations. |
| T1027.013 Encrypted/Encoded File |
GroupThreat Group-3390 | A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder. |
| T1027.015 Compression |
GroupThreat Group-3390 | Threat Group-3390 malware is compressed with LZNT1 compression. |
| T1046 Network Service Discovery |
GroupThreat Group-3390 | Threat Group-3390 actors use the Hunter tool to conduct network service discovery for vulnerable systems. |
| T1055 Process Injection |
MalwareHyperBro | HyperBro can run shellcode it injects into a newly created process. |
| T1059.003 Windows Command Shell |
GroupThreat Group-3390 | Threat Group-3390 has used command-line interfaces for execution. |
| T1070.004 File Deletion |
MalwareHyperBro | HyperBro has the ability to delete a specified file. |
| T1071.001 Web Protocols |
MalwareHyperBro | HyperBro has used HTTPS for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareHyperBro | HyperBro has the ability to download additional files. |
| T1106 Native API |
MalwareHyperBro | HyperBro has the ability to run an application ( |
| T1113 Screen Capture |
MalwareHyperBro | HyperBro has the ability to take screenshots. |
| T1210 Exploitation of Remote Services |
GroupThreat Group-3390 | Threat Group-3390 has exploited MS17-010 to move laterally to other systems on the network. |
| T1505.003 Web Shell |
GroupThreat Group-3390 | Threat Group-3390 has used a variety of Web shells. |
| T1569.002 Service Execution |
MalwareHyperBro | HyperBro has the ability to start and stop a specified service. |
| T1574.001 DLL |
MalwareHyperBro | HyperBro has used a legitimate application to sideload a DLL to decrypt, decompress, and run a payload. |
| T1574.001 DLL |
GroupThreat Group-3390 | Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler. |
| T1588.002 Tool |
GroupThreat Group-3390 | Threat Group-3390 has obtained and used tools such as Impacket, pwdump, Mimikatz, gsecdump, NBTscan, and Windows Credential Editor. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.