Microsoft Defender Research Team. (2018, December 3). Analysis of cyberattack on U.S. think tanks, non-profits, public sector by unidentified attackers. Retrieved April 15, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.009 Embedded Payloads |
CampaignC0021 | For C0021, the threat actors embedded a base64-encoded payload within a LNK file. |
| T1027.010 Command Obfuscation |
CampaignC0021 | During C0021, the threat actors used encoded PowerShell commands. |
| T1059.001 PowerShell |
CampaignC0021 | During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file. |
| T1105 Ingress Tool Transfer |
CampaignC0021 | During C0021, the threat actors downloaded additional tools and files onto victim machines. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignC0021 | During C0021, the threat actors deobfuscated encoded PowerShell commands including use of the specific string `'FromBase'+0x40+'String'`, in place of `FromBase64String` which is normally used to decode base64. |
| T1566.002 Spearphishing Link |
CampaignC0021 | During C0021, the threat actors sent phishing emails with unique malicious links, likely for tracking victim clicks. |
| T1584.001 Domains |
CampaignC0021 | For C0021, the threat actors used legitimate but compromised domains to host malicious payloads. |
| T1588.002 Tool |
CampaignC0021 | For C0021, the threat actors used Cobalt Strike configured with a modified variation of the publicly available Pandora Malleable C2 Profile. |
| T1608.001 Upload Malware |
CampaignC0021 | For C0021, the threat actors uploaded malware to websites under their control. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.