N. Baisini. (2022, July 13). Transparent Tribe begins targeting education sector in latest campaign. Retrieved September 22, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareCrimson | Crimson can collect information from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareCrimson | Crimson can identify the user on a targeted system. |
| T1041 Exfiltration Over C2 Channel |
MalwareCrimson | Crimson can exfiltrate stolen information over its C2. |
| T1056.001 Keylogging |
MalwareCrimson | Crimson can use a module to perform keylogging on compromised hosts. |
| T1057 Process Discovery |
MalwareCrimson | Crimson contains a command to list processes. |
| T1059.005 Visual Basic |
CampaignC0011 | For C0011, Transparent Tribe used malicious VBA macros within a lure document as part of the Crimson malware installation process onto a compromised host. |
| T1070.004 File Deletion |
MalwareCrimson | Crimson has the ability to delete files from a compromised host. |
| T1082 System Information Discovery |
MalwareCrimson | Crimson contains a command to collect the victim PC name and operating system. |
| T1083 File and Directory Discovery |
MalwareCrimson | Crimson contains commands to list files and directories, as well as search for files matching certain extensions from a defined list. |
| T1105 Ingress Tool Transfer |
MalwareCrimson | Crimson contains a command to retrieve files from its C2 server. |
| T1113 Screen Capture |
MalwareCrimson | Crimson contains a command to perform screen captures. |
| T1204.001 Malicious Link |
CampaignC0011 | During C0011, Transparent Tribe relied on student targets to click on a malicious link sent via email. |
| T1204.002 Malicious File |
CampaignC0011 | During C0011, Transparent Tribe relied on a student target to open a malicious document delivered via email. |
| T1566.001 Spearphishing Attachment |
CampaignC0011 | During C0011, Transparent Tribe sent malicious attachments via email to student targets in India. |
| T1566.002 Spearphishing Link |
CampaignC0011 | During C0011, Transparent Tribe sent emails containing a malicious link to student targets in India. |
| T1583.001 Domains |
CampaignC0011 | For C0011, Transparent Tribe registered domains likely designed to appear relevant to student targets in India. |
| T1587.003 Digital Certificates |
CampaignC0011 | For C0011, Transparent Tribe established SSL certificates on the typo-squatted domains the group registered. |
| T1608.001 Upload Malware |
CampaignC0011 | For C0011, Transparent Tribe hosted malicious documents on domains registered by the group. |
| T1680 Local Storage Discovery |
MalwareCrimson | Crimson contains a command to collect disk drive information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.