Alintanahin, K. (2015). Operation Tropic Trooper: Relying on Tried-and-Tested Flaws to Infiltrate Secret Keepers. Retrieved June 14, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareYAHOYAH | YAHOYAH encrypts its configuration file using a simple algorithm. |
| T1033 System Owner/User Discovery |
GroupTropic Trooper | Tropic Trooper used |
| T1046 Network Service Discovery |
GroupTropic Trooper | Tropic Trooper used |
| T1071.001 Web Protocols |
MalwareYAHOYAH | YAHOYAH uses HTTP for C2. |
| T1082 System Information Discovery |
GroupTropic Trooper | Tropic Trooper has detected a target system’s OS version. |
| T1082 System Information Discovery |
MalwareYAHOYAH | YAHOYAH checks for the system’s Windows OS version and hostname. |
| T1105 Ingress Tool Transfer |
MalwareYAHOYAH | YAHOYAH uses HTTP GET requests to download other files that are executed in memory. |
| T1135 Network Share Discovery |
GroupTropic Trooper | Tropic Trooper used |
| T1140 Deobfuscate/Decode Files or Information |
MalwareYAHOYAH | YAHOYAH decrypts downloaded files before execution. |
| T1518.001 Security Software Discovery |
MalwareYAHOYAH | YAHOYAH checks for antimalware solution processes on the system. |
| T1566.001 Spearphishing Attachment |
GroupTropic Trooper | Tropic Trooper sent spearphishing emails that contained malicious Microsoft Office and fake installer file attachments. |
| T1680 Local Storage Discovery |
GroupTropic Trooper | Tropic Trooper has detected a target system’s system volume information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.