Dunwoody, M., et al. (2018, November 19). Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign. Retrieved November 27, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
CampaignC0021 | During C0021, the threat actors used encoded PowerShell commands. |
| T1059.001 PowerShell |
CampaignC0021 | During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file. |
| T1071.001 Web Protocols |
CampaignC0021 | During C0021, the threat actors used HTTP for some of their C2 communications. |
| T1095 Non-Application Layer Protocol |
CampaignC0021 | During C0021, the threat actors used TCP for some C2 communications. |
| T1105 Ingress Tool Transfer |
CampaignC0021 | During C0021, the threat actors downloaded additional tools and files onto victim machines. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignC0021 | During C0021, the threat actors deobfuscated encoded PowerShell commands including use of the specific string `'FromBase'+0x40+'String'`, in place of `FromBase64String` which is normally used to decode base64. |
| T1204.001 Malicious Link |
CampaignC0021 | During C0021, the threat actors lured users into clicking a malicious link which led to the download of a ZIP archive containing a malicious .LNK file. |
| T1218.011 Rundll32 |
CampaignC0021 | During C0021, the threat actors used `rundll32.exe` to execute the Cobalt Strike Beacon loader DLL. |
| T1566.002 Spearphishing Link |
CampaignC0021 | During C0021, the threat actors sent phishing emails with unique malicious links, likely for tracking victim clicks. |
| T1573.002 Asymmetric Cryptography |
CampaignC0021 | During C0021, the threat actors used SSL via TCP port 443 for C2 communications. |
| T1583.001 Domains |
CampaignC0021 | For C0021, the threat actors registered domains for use in C2. |
| T1588.002 Tool |
CampaignC0021 | For C0021, the threat actors used Cobalt Strike configured with a modified variation of the publicly available Pandora Malleable C2 Profile. |
| T1608.001 Upload Malware |
CampaignC0021 | For C0021, the threat actors uploaded malware to websites under their control. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.