Moore, S. et al. (2020, April 30). Anomali Suspects that China-Backed APT Pirate Panda May Be Seeking Access to Vietnam Government Data Center. Retrieved May 19, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
GroupTropic Trooper | Tropic Trooper has used HTTP in communication with the C2. |
| T1204.002 Malicious File |
GroupTropic Trooper | Tropic Trooper has lured victims into executing malware via malicious e-mail attachments. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTropic Trooper | Tropic Trooper has created shortcuts in the Startup folder to establish persistence. |
| T1566.001 Spearphishing Attachment |
GroupTropic Trooper | Tropic Trooper sent spearphishing emails that contained malicious Microsoft Office and fake installer file attachments. |
| T1574.001 DLL |
GroupTropic Trooper | Tropic Trooper has been known to side-load DLLs using a valid version of a Windows Address Book and Windows Defender executable with one of their tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.