ATT&CKReferencesTrend Micro TA505 June 2019

Trend Micro TA505 June 2019

Hiroaki, H. and Lu, L. (2019, June 12). Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns. Retrieved May 29, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwareServHelper

ServHelper has the ability to execute a PowerShell script to get information from the infected host.

T1059.003
Windows Command Shell
GroupTA505

TA505 has executed commands using cmd.exe.

T1059.005
Visual Basic
GroupTA505

TA505 has used VBS for code execution.

T1069
Permission Groups Discovery
GroupTA505

TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run net group /domain.

T1087.003
Email Account
GroupTA505

TA505 has used the tool EmailStealer to steal and send lists of e-mail addresses to a remote server.

T1204.001
Malicious Link
GroupTA505

TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1204.002
Malicious File
GroupTA505

TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1218.007
Msiexec
GroupTA505

TA505 has used msiexec to download and execute malicious Windows Installer files.

T1553.002
Code Signing
GroupTA505

TA505 has signed payloads with code signing certificates from Thawte and Sectigo.

T1566.001
Spearphishing Attachment
GroupTA505

TA505 has used spearphishing emails with malicious attachments to initially compromise victims.

T1566.002
Spearphishing Link
GroupTA505

TA505 has sent spearphishing emails containing malicious links.

T1568.001
Fast Flux DNS
GroupTA505

TA505 has used fast flux to mask botnets by distributing payloads across multiple IPs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.