ATT&CKReferencesSecurelist Dropping Elephant

Securelist Dropping Elephant

Kaspersky Lab's Global Research & Analysis Team. (2016, July 8). The Dropping Elephant – aggressive cyber-espionage in the Asian region. Retrieved August 3, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1027.002
Software Packing
GroupPatchwork

A Patchwork payload was packed with UPX.

T1102.001
Dead Drop Resolver
GroupPatchwork

Patchwork hides base64-encoded and encrypted C2 server locations in comments on legitimate websites.

T1105
Ingress Tool Transfer
GroupPatchwork

Patchwork payloads download additional files from the C2 server.

T1203
Exploitation for Client Execution
GroupPatchwork

Patchwork uses malicious documents to deliver remote execution exploits as part of. The group has previously exploited CVE-2017-8570, CVE-2012-1856, CVE-2014-4114, CVE-2017-0199, CVE-2017-11882, and CVE-2015-1641.

T1566.001
Spearphishing Attachment
GroupPatchwork

Patchwork has used spearphishing with an attachment to deliver files with exploits to initial victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.