ATT&CKReferencesFireEye APT40 March 2019

FireEye APT40 March 2019

Plan, F., et al. (2019, March 4). APT40: Examining a China-Nexus Espionage Actor. Retrieved March 18, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupLeviathan

Leviathan has used publicly available tools to dump password hashes, including HOMEFRY.

T1003.001
LSASS Memory
GroupLeviathan

Leviathan has used publicly available tools to dump password hashes, including ProcDump and WCE.

T1021.001
Remote Desktop Protocol
GroupLeviathan

Leviathan has targeted RDP credentials and used it to move through the victim environment.

T1021.004
SSH
GroupLeviathan

Leviathan used ssh for internal reconnaissance.

T1505.003
Web Shell
GroupLeviathan

Leviathan relies on web shells for an initial foothold as well as persistence into the victim's systems.

T1553.002
Code Signing
GroupLeviathan

Leviathan has used stolen code signing certificates to sign malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.