Lee, B., Falcone, R. (2018, December 12). Dear Joohn: The Sofacy Group’s Global Campaign. Retrieved April 19, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareZebrocy | Zebrocy's Delphi variant was packed with UPX. |
| T1047 Windows Management Instrumentation |
MalwareZebrocy | One variant of Zebrocy uses WMI queries to gather information. |
| T1057 Process Discovery |
MalwareCannon | Cannon can obtain a list of processes running on the system. |
| T1057 Process Discovery |
MalwareZebrocy | Zebrocy uses the |
| T1071.001 Web Protocols |
MalwareZebrocy | Zebrocy uses HTTP for C2. |
| T1071.003 Mail Protocols |
MalwareZebrocy | Zebrocy uses SMTP and POP3 for C2. |
| T1082 System Information Discovery |
MalwareCannon | Cannon can gather system information from the victim’s machine such as the OS version, and machine name. |
| T1082 System Information Discovery |
MalwareZebrocy | Zebrocy collects the OS version and computer name. Zebrocy also runs the |
| T1113 Screen Capture |
MalwareZebrocy | A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format. |
| T1221 Template Injection |
GroupAPT28 | APT28 used weaponized Microsoft Word documents abusing the remote template function to retrieve a malicious macro. |
| T1680 Local Storage Discovery |
MalwareCannon | Cannon can gather drive information from the victim's machine. |
| T1680 Local Storage Discovery |
MalwareZebrocy | Zebrocy collects the serial number for the storage volume C:\. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.