Rusu, B. (2020, May 21). Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia. Retrieved May 22, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupAPT39 | APT39 has used different versions of Mimikatz to obtain credentials. |
| T1018 Remote System Discovery |
GroupAPT39 | APT39 has used NBTscan and custom tools to discover remote systems. |
| T1021.001 Remote Desktop Protocol |
GroupAPT39 | APT39 has been seen using RDP for lateral movement and persistence, in some cases employing the rdpwinst tool for mangement of multiple sessions. |
| T1027.002 Software Packing |
GroupAPT39 | APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT39 | APT39 has used malware disguised as Mozilla Firefox and a tool named mfevtpse.exe to proxy C2 communications, closely mimicking a legitimate McAfee file mfevtps.exe. |
| T1046 Network Service Discovery |
GroupAPT39 | APT39 has used CrackMapExec and a custom port scanner known as BLUETORCH for network scanning. |
| T1053.005 Scheduled Task |
GroupAPT39 | APT39 has created scheduled tasks for persistence. |
| T1059.001 PowerShell |
GroupAPT39 | APT39 has used PowerShell to execute malicious code. |
| T1059.006 Python |
GroupAPT39 | APT39 has used a command line utility and a network scanner written in python. |
| T1071.001 Web Protocols |
GroupAPT39 | APT39 has used HTTP in communications with C2. |
| T1071.004 DNS |
GroupAPT39 | APT39 has used remote access tools that leverage DNS in communications with C2. |
| T1090.001 Internal Proxy |
GroupAPT39 | APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts. |
| T1090.002 External Proxy |
GroupAPT39 | APT39 has used various tools to proxy C2 communications. |
| T1102.002 Bidirectional Communication |
GroupAPT39 | APT39 has communicated with C2 through files uploaded to and downloaded from DropBox. |
| T1135 Network Share Discovery |
GroupAPT39 | APT39 has used the post exploitation tool CrackMapExec to enumerate network shares. |
| T1136.001 Local Account |
GroupAPT39 | APT39 has created accounts on multiple compromised hosts to perform actions within the network. |
| T1204.002 Malicious File |
GroupAPT39 | APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious attachment. |
| T1555 Credentials from Password Stores |
GroupAPT39 | APT39 has used the Smartftp Password Decryptor tool to decrypt FTP passwords. |
| T1569.002 Service Execution |
GroupAPT39 | APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes. |
| T1588.002 Tool |
GroupAPT39 | APT39 has modified and used customized versions of publicly-available tools like PLINK and Mimikatz. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.