Billy Leonard. (2023, April 19). Ukraine remains Russia’s biggest cyber focus in 2023. Retrieved March 1, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036 Masquerading |
GroupSandworm Team | Sandworm Team masqueraded malicious installers as Windows update packages to evade defense and entice users to execute binaries. |
| T1189 Drive-by Compromise |
GroupAPT28 | APT28 has compromised targets via strategic web compromise utilizing custom exploit kits. APT28 used reflected cross-site scripting (XSS) against government websites to redirect users to phishing webpages. |
| T1190 Exploit Public-Facing Application |
GroupSandworm Team | Sandworm Team exploits public-facing applications for initial access and to acquire infrastructure, such as exploitation of the EXIM mail transfer agent in Linux systems. |
| T1213.006 Databases |
GroupSandworm Team | Sandworm Team exfiltrates data of interest from enterprise databases using Adminer. |
| T1539 Steal Web Session Cookie |
GroupSandworm Team | Sandworm Team used information stealer malware to collect browser session cookies. |
| T1583 Acquire Infrastructure |
GroupSandworm Team | Sandworm Team used various third-party email campaign management services to deliver phishing emails. |
| T1583.003 Virtual Private Server |
GroupAPT28 | APT28 hosted phishing domains on free services for brief periods of time during campaigns. |
| T1584.004 Server |
GroupSandworm Team | Sandworm Team compromised legitimate Linux servers running the EXIM mail transfer agent for use in subsequent campaigns. |
| T1584.008 Network Devices |
GroupAPT28 | APT28 compromised Ubiquiti network devices to act as collection devices for credentials compromised via phishing webpages. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.