Plan, F., et al. (2019, March 4). APT40: Examining a China-Nexus Espionage Actor. Retrieved March 18, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupLeviathan | Leviathan has used publicly available tools to dump password hashes, including HOMEFRY. |
| T1003.001 LSASS Memory |
GroupLeviathan | Leviathan has used publicly available tools to dump password hashes, including ProcDump and WCE. |
| T1021.001 Remote Desktop Protocol |
GroupLeviathan | Leviathan has targeted RDP credentials and used it to move through the victim environment. |
| T1021.004 SSH |
GroupLeviathan | Leviathan used ssh for internal reconnaissance. |
| T1505.003 Web Shell |
GroupLeviathan | Leviathan relies on web shells for an initial foothold as well as persistence into the victim's systems. |
| T1553.002 Code Signing |
GroupLeviathan | Leviathan has used stolen code signing certificates to sign malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.