aptsim

valsmith. (2012, September 21). More on APTSim. Retrieved September 28, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupAPT3

APT3 will identify Microsoft Office documents on the victim's computer.

T1021.001
Remote Desktop Protocol
GroupAPT3

APT3 enables the Remote Desktop Protocol for persistence. APT3 has also interacted with compromised systems to browse and copy files through RDP sessions.

T1036.010
Masquerade Account Name
GroupAPT3

APT3 has been known to create or enable accounts, such as support_388945a0.

T1074.001
Local Data Staging
GroupAPT3

APT3 has been known to stage files for exfiltration in a single location.

T1098.007
Additional Local or Domain Groups
GroupAPT3

APT3 has been known to add created accounts to local admin groups to maintain elevated access.

T1136.001
Local Account
GroupAPT3

APT3 has been known to create or enable accounts, such as support_388945a0.

T1546.008
Accessibility Features
GroupAPT3

APT3 replaces the Sticky Keys binary C:\Windows\System32\sethc.exe for persistence.

T1560.001
Archive via Utility
GroupAPT3

APT3 has used tools to compress data before exfilling it.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.