DiMaggio, J. (2016, May 17). Indian organizations targeted in Suckfly attacks. Retrieved August 3, 2016.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupSuckfly | Suckfly used a signed credential-dumping tool to obtain victim account credentials. |
| T1046 Network Service Discovery |
GroupSuckfly | Suckfly the victim's internal network for hosts with ports 8080, 5900, and 40 open. |
| T1059.003 Windows Command Shell |
GroupSuckfly | Several tools used by Suckfly have been command-line driven. |
| T1078 Valid Accounts |
GroupSuckfly | Suckfly used legitimate account credentials that they dumped to navigate the internal victim network as though they were the legitimate account owner. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.