FireEye. (2021, May 11). Shining a Light on DARKSIDE Ransomware Operations. Retrieved September 22, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwareSMOKEDHAM | SMOKEDHAM can continuously capture keystrokes. |
| T1102 Web Service |
MalwareSMOKEDHAM | SMOKEDHAM has used Google Drive and Dropbox to host files downloaded by victims via malicious links. |
| T1113 Screen Capture |
MalwareSMOKEDHAM | SMOKEDHAM can capture screenshots of the victim’s desktop. |
| T1204.001 Malicious Link |
MalwareSMOKEDHAM | SMOKEDHAM has relied upon users clicking on a malicious link delivered through phishing. |
| T1598.003 Spearphishing Link |
MalwareSMOKEDHAM | SMOKEDHAM has been delivered via malicious links in phishing emails. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.