Check Point. (2021, April 8). Iran’s APT34 Returns with an Updated Arsenal. Retrieved May 5, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareSideTwist | SideTwist can embed C2 responses in the source code of a fake Flickr webpage. |
| T1005 Data from Local System |
MalwareSideTwist | SideTwist has the ability to upload files from a compromised host. |
| T1008 Fallback Channels |
MalwareSideTwist | SideTwist has primarily used port 443 for C2 but can use port 80 as a fallback. |
| T1016 System Network Configuration Discovery |
MalwareSideTwist | SideTwist has the ability to collect the domain name on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareSideTwist | SideTwist can collect the username on a targeted system. |
| T1033 System Owner/User Discovery |
GroupOilRig | OilRig has run |
| T1036 Masquerading |
GroupOilRig | OilRig has used .doc file extensions to mask malicious executables. |
| T1041 Exfiltration Over C2 Channel |
MalwareSideTwist | SideTwist has exfiltrated data over its C2 channel. |
| T1053.005 Scheduled Task |
GroupOilRig | OilRig has created scheduled tasks that run a VBScript to execute a payload on victim machines. |
| T1059.003 Windows Command Shell |
MalwareSideTwist | SideTwist can execute shell commands on a compromised host. |
| T1059.005 Visual Basic |
GroupOilRig | OilRig has used VBScript macros for execution on compromised hosts. |
| T1071.001 Web Protocols |
MalwareSideTwist | SideTwist has used HTTP GET and POST requests over port 443 for C2. |
| T1071.004 DNS |
GroupOilRig | OilRig has used DNS for C2 including the publicly available |
| T1082 System Information Discovery |
MalwareSideTwist | SideTwist can collect the computer name of a targeted system. |
| T1082 System Information Discovery |
GroupOilRig | OilRig has run |
| T1083 File and Directory Discovery |
MalwareSideTwist | SideTwist has the ability to search for specific files. |
| T1105 Ingress Tool Transfer |
MalwareSideTwist | SideTwist has the ability to download additional files. |
| T1106 Native API |
MalwareSideTwist | SideTwist can use |
| T1120 Peripheral Device Discovery |
GroupOilRig | OilRig has used tools to identify if a mouse is connected to a targeted system. |
| T1132.001 Standard Encoding |
MalwareSideTwist | SideTwist has used Base64 for encoded C2 traffic. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSideTwist | SideTwist can decode and decrypt messages received from C2. |
| T1204.002 Malicious File |
GroupOilRig | OilRig has delivered macro-enabled documents that required targets to click the "enable content" button to execute the payload on the system. |
| T1497.001 System Checks |
GroupOilRig | OilRig has used macros to verify if a mouse is connected to a compromised machine. |
| T1573.001 Symmetric Cryptography |
MalwareSideTwist | SideTwist can encrypt C2 communications with a randomly generated key. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.