Symantec. (2018, February 28). Chafer: Latest Attacks Reveal Heightened Ambitions. Retrieved May 22, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupAPT39 | APT39 has used various tools to steal files from the compromised host. |
| T1018 Remote System Discovery |
GroupAPT39 | APT39 has used NBTscan and custom tools to discover remote systems. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT39 | APT39 has used SMB for lateral movement. |
| T1056.001 Keylogging |
GroupAPT39 | APT39 has used tools for capturing keystrokes. |
| T1059.001 PowerShell |
GroupAPT39 | APT39 has used PowerShell to execute malicious code. |
| T1105 Ingress Tool Transfer |
GroupAPT39 | APT39 has downloaded tools to compromised hosts. |
| T1113 Screen Capture |
GroupAPT39 | APT39 has used a screen capture utility to take screenshots on a compromised host. |
| T1115 Clipboard Data |
GroupAPT39 | APT39 has used tools capable of stealing contents of the clipboard. |
| T1190 Exploit Public-Facing Application |
GroupAPT39 | APT39 has used SQL injection for initial compromise. |
| T1204.002 Malicious File |
GroupAPT39 | APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious attachment. |
| T1566.001 Spearphishing Attachment |
GroupAPT39 | APT39 leveraged spearphishing emails with malicious attachments to initially compromise victims. |
| T1569.002 Service Execution |
GroupAPT39 | APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.