Crowdstrike. (2020, March 2). 2020 Global Threat Report. Retrieved December 11, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
GroupFIN7 | FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails. |
| T1014 Rootkit |
GroupAPT41 | APT41 deployed rootkits on Linux systems. |
| T1021.001 Remote Desktop Protocol |
GroupOilRig | OilRig has used Remote Desktop Protocol for lateral movement. The group has also used tunneling tools to tunnel RDP into the environment. |
| T1021.001 Remote Desktop Protocol |
GroupAPT41 | APT41 used RDP for lateral movement. APT41 used NATBypass to expose local RDP ports on compromised systems to the Internet. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT41 | APT41 has transferred implant files using Windows Admin Shares and the Server Message Block (SMB) protocol, then executes files through Windows Management Instrumentation (WMI). |
| T1053.005 Scheduled Task |
GroupAPT41 | APT41 used a compromised account to create a scheduled task on a system. |
| T1053.005 Scheduled Task |
MalwareBabyShark | BabyShark has used scheduled tasks to maintain persistence. |
| T1059.005 Visual Basic |
GroupKimsuky | Kimsuky has used Visual Basic to download malicious payloads. Kimsuky has also used malicious VBA macros within maldocs disguised as forms that trigger when a victim types any content into the lure. Kimsuky has also leveraged VBScript (VBS) scripts to execute temp.vbs every 19 minutes using a scheduled task to run QuasarRAT. |
| T1071.003 Mail Protocols |
GroupTurla | Turla has used multiple backdoors which communicate with a C2 server via email attachments. |
| T1078 Valid Accounts |
GroupOilRig | OilRig has used compromised credentials to access other systems on a victim network. |
| T1078 Valid Accounts |
GroupAPT41 | APT41 used compromised credentials to log on to other systems. |
| T1105 Ingress Tool Transfer |
GroupKimsuky | Kimsuky has downloaded additional scripts, tools, and malware onto victim systems. |
| T1105 Ingress Tool Transfer |
GroupAPT41 | APT41 used certutil to download additional files. APT41 downloaded post-exploitation tools such as Cobalt Strike via command shell following initial access. APT41 has uploaded Procdump and NATBypass to a staging directory and has used these tools in follow-on activities. |
| T1112 Modify Registry |
GroupKimsuky | Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck. |
| T1140 Deobfuscate/Decode Files or Information |
GroupOilRig | A OilRig macro has run a PowerShell command to decode file contents. OilRig has also used certutil to decode base64-encoded files on victims. |
| T1195.002 Compromise Software Supply Chain |
GroupCobalt Group | Cobalt Group has compromised legitimate web browser updates to deliver a backdoor. |
| T1197 BITS Jobs |
GroupAPT41 | |
| T1218.005 Mshta |
GroupKimsuky | Kimsuky has used mshta.exe to run malicious scripts on the system. |
| T1218.011 Rundll32 |
GroupAPT41 | APT41 has used rundll32.exe to execute a loader. |
| T1219.002 Remote Desktop Software |
GroupKimsuky | Kimsuky has used a modified TeamViewer client as a command and control channel. |
| T1505.003 Web Shell |
GroupOilRig | OilRig has used web shells, often to maintain access to a victim network. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupKimsuky | Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key. |
| T1574.001 DLL |
GroupAPT41 | APT41 has used search order hijacking to execute malicious payloads, such as Winnti for Windows. APT41 has also used legitimate executables to perform DLL side-loading of their malware. |
| T1574.006 Dynamic Linker Hijacking |
GroupAPT41 | APT41 has configured payloads to load via LD_PRELOAD. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.