Bromiley, M., et al.. (2019, July 18). Hard Pass: Declining APT34’s Invite to Join Their Professional Network. Retrieved August 26, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupOilRig | OilRig has used credential dumping tools such as Mimikatz to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.004 LSA Secrets |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.005 Cached Domain Credentials |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1053.005 Scheduled Task |
GroupOilRig | OilRig has created scheduled tasks that run a VBScript to execute a payload on victim machines. |
| T1056.001 Keylogging |
GroupOilRig | OilRig has employed keyloggers including KEYPUNCH and LONGWATCH. |
| T1071.001 Web Protocols |
GroupOilRig | OilRig has used HTTP for C2. |
| T1071.004 DNS |
GroupOilRig | OilRig has used DNS for C2 including the publicly available |
| T1082 System Information Discovery |
GroupOilRig | OilRig has run |
| T1552.001 Credentials In Files |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1555 Credentials from Password Stores |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1555.003 Credentials from Web Browsers |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers. |
| T1555.004 Windows Credential Manager |
GroupOilRig | OilRig has used credential dumping tool named VALUEVAULT to steal credentials from the Windows Credential Manager. |
| T1566.003 Spearphishing via Service |
GroupOilRig | OilRig has used LinkedIn to send spearphishing links. |
| T1572 Protocol Tunneling |
GroupOilRig | OilRig has used the Plink utility and other tools to create tunnels to C2 servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.