Guerrero-Saade, J. (2021, June 1). NobleBaron | New Poisoned Installers Could Be Used In Supply Chain Attacks. Retrieved August 4, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.001 Binary Padding |
GroupAPT29 | APT29 used large size files to avoid detection by security solutions with hardcoded size limits. |
| T1036 Masquerading |
MalwareNativeZone | NativeZone has, upon execution, displayed a message box that appears to be related to a Ukrainian electronic document management system. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT29 | APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal. |
| T1218.011 Rundll32 |
MalwareNativeZone | NativeZone has used rundll32 to execute a malicious DLL. |
| T1480 Execution Guardrails |
MalwareNativeZone | NativeZone can check for the presence of KM.EkeyAlmaz1C.dll and will halt execution unless it is in the same directory as the rest of the malware's components. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.