ATT&CKReferencesTrendMicro TropicTrooper 2015

TrendMicro TropicTrooper 2015

Alintanahin, K. (2015). Operation Tropic Trooper: Relying on Tried-and-Tested Flaws to Infiltrate Secret Keepers. Retrieved June 14, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareYAHOYAH

YAHOYAH encrypts its configuration file using a simple algorithm.

T1033
System Owner/User Discovery
GroupTropic Trooper

Tropic Trooper used letmein to scan for saved usernames on the target system.

T1046
Network Service Discovery
GroupTropic Trooper

Tropic Trooper used pr and an openly available tool to scan for open ports on target systems.

T1071.001
Web Protocols
MalwareYAHOYAH

YAHOYAH uses HTTP for C2.

T1082
System Information Discovery
GroupTropic Trooper

Tropic Trooper has detected a target system’s OS version.

T1082
System Information Discovery
MalwareYAHOYAH

YAHOYAH checks for the system’s Windows OS version and hostname.

T1105
Ingress Tool Transfer
MalwareYAHOYAH

YAHOYAH uses HTTP GET requests to download other files that are executed in memory.

T1135
Network Share Discovery
GroupTropic Trooper

Tropic Trooper used netview to scan target systems for shared resources.

T1140
Deobfuscate/Decode Files or Information
MalwareYAHOYAH

YAHOYAH decrypts downloaded files before execution.

T1518.001
Security Software Discovery
MalwareYAHOYAH

YAHOYAH checks for antimalware solution processes on the system.

T1566.001
Spearphishing Attachment
GroupTropic Trooper

Tropic Trooper sent spearphishing emails that contained malicious Microsoft Office and fake installer file attachments.

T1680
Local Storage Discovery
GroupTropic Trooper

Tropic Trooper has detected a target system’s system volume information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.