Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016.001 Internet Connection Discovery |
MalwareMore_eggs | More_eggs has used HTTP GET requests to check internet connectivity. |
| T1033 System Owner/User Discovery |
MalwareMore_eggs | More_eggs has the capability to gather the username from the victim's machine. |
| T1047 Windows Management Instrumentation |
GroupFIN6 | FIN6 has used WMI to automate the remote execution of PowerShell scripts. |
| T1059.003 Windows Command Shell |
MalwareMore_eggs | More_eggs has used cmd.exe for execution. |
| T1070.004 File Deletion |
MalwareMore_eggs | More_eggs can remove itself from a system. |
| T1071.001 Web Protocols |
MalwareMore_eggs | More_eggs uses HTTPS for C2. |
| T1082 System Information Discovery |
MalwareMore_eggs | More_eggs has the capability to gather the OS version and computer name. |
| T1105 Ingress Tool Transfer |
MalwareMore_eggs | More_eggs can download and launch additional payloads. |
| T1132.001 Standard Encoding |
MalwareMore_eggs | More_eggs has used basE91 encoding, along with encryption, for C2 communication. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMore_eggs | More_eggs will decode malware components that are then dropped to the system. |
| T1218.010 Regsvr32 |
MalwareMore_eggs | More_eggs has used regsvr32.exe to execute the malicious DLL. |
| T1553.002 Code Signing |
GroupFIN6 | FIN6 has used Comodo code-signing certificates. |
| T1553.002 Code Signing |
MalwareMore_eggs | More_eggs has used a signed binary shellcode loader and a signed Dynamic Link Library (DLL) to create a reverse shell. |
| T1566.003 Spearphishing via Service |
GroupFIN6 | FIN6 has used fake job advertisements sent via LinkedIn to spearphish targets. |
| T1573.001 Symmetric Cryptography |
MalwareMore_eggs | More_eggs has used an RC4-based encryption method for its C2 communications. |
| T1588.002 Tool |
GroupFIN6 | FIN6 has obtained and used tools such as Mimikatz, Cobalt Strike, and AdFind. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.