ATT&CKReferencesLeonard TAG 2023

Leonard TAG 2023

Billy Leonard. (2023, April 19). Ukraine remains Russia’s biggest cyber focus in 2023. Retrieved March 1, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1036
Masquerading
GroupSandworm Team

Sandworm Team masqueraded malicious installers as Windows update packages to evade defense and entice users to execute binaries.

T1189
Drive-by Compromise
GroupAPT28

APT28 has compromised targets via strategic web compromise utilizing custom exploit kits. APT28 used reflected cross-site scripting (XSS) against government websites to redirect users to phishing webpages.

T1190
Exploit Public-Facing Application
GroupSandworm Team

Sandworm Team exploits public-facing applications for initial access and to acquire infrastructure, such as exploitation of the EXIM mail transfer agent in Linux systems.

T1213.006
Databases
GroupSandworm Team

Sandworm Team exfiltrates data of interest from enterprise databases using Adminer.

T1539
Steal Web Session Cookie
GroupSandworm Team

Sandworm Team used information stealer malware to collect browser session cookies.

T1583
Acquire Infrastructure
GroupSandworm Team

Sandworm Team used various third-party email campaign management services to deliver phishing emails.

T1583.003
Virtual Private Server
GroupAPT28

APT28 hosted phishing domains on free services for brief periods of time during campaigns.

T1584.004
Server
GroupSandworm Team

Sandworm Team compromised legitimate Linux servers running the EXIM mail transfer agent for use in subsequent campaigns.

T1584.008
Network Devices
GroupAPT28

APT28 compromised Ubiquiti network devices to act as collection devices for credentials compromised via phishing webpages.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.