ATT&CKReferencesSymantec Suckfly May 2016

Symantec Suckfly May 2016

DiMaggio, J. (2016, May 17). Indian organizations targeted in Suckfly attacks. Retrieved August 3, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupSuckfly

Suckfly used a signed credential-dumping tool to obtain victim account credentials.

T1046
Network Service Discovery
GroupSuckfly

Suckfly the victim's internal network for hosts with ports 8080, 5900, and 40 open.

T1059.003
Windows Command Shell
GroupSuckfly

Several tools used by Suckfly have been command-line driven.

T1078
Valid Accounts
GroupSuckfly

Suckfly used legitimate account credentials that they dumped to navigate the internal victim network as though they were the legitimate account owner.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.