valsmith. (2012, September 21). More on APTSim. Retrieved September 28, 2017.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupAPT3 | APT3 will identify Microsoft Office documents on the victim's computer. |
| T1021.001 Remote Desktop Protocol |
GroupAPT3 | APT3 enables the Remote Desktop Protocol for persistence. APT3 has also interacted with compromised systems to browse and copy files through RDP sessions. |
| T1036.010 Masquerade Account Name |
GroupAPT3 | APT3 has been known to create or enable accounts, such as |
| T1074.001 Local Data Staging |
GroupAPT3 | APT3 has been known to stage files for exfiltration in a single location. |
| T1098.007 Additional Local or Domain Groups |
GroupAPT3 | APT3 has been known to add created accounts to local admin groups to maintain elevated access. |
| T1136.001 Local Account |
GroupAPT3 | APT3 has been known to create or enable accounts, such as |
| T1546.008 Accessibility Features |
GroupAPT3 | APT3 replaces the Sticky Keys binary |
| T1560.001 Archive via Utility |
GroupAPT3 | APT3 has used tools to compress data before exfilling it. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.