Hiroaki, H. and Lu, L. (2019, June 12). Shifting Tactics: Breaking Down TA505 Group’s Use of HTML, RATs and Other Techniques in Latest Campaigns. Retrieved May 29, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
MalwareServHelper | ServHelper has the ability to execute a PowerShell script to get information from the infected host. |
| T1059.003 Windows Command Shell |
GroupTA505 | TA505 has executed commands using |
| T1059.005 Visual Basic |
GroupTA505 | TA505 has used VBS for code execution. |
| T1069 Permission Groups Discovery |
GroupTA505 | TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run |
| T1087.003 Email Account |
GroupTA505 | TA505 has used the tool EmailStealer to steal and send lists of e-mail addresses to a remote server. |
| T1204.001 Malicious Link |
GroupTA505 | TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1204.002 Malicious File |
GroupTA505 | TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1218.007 Msiexec |
GroupTA505 | TA505 has used |
| T1553.002 Code Signing |
GroupTA505 | TA505 has signed payloads with code signing certificates from Thawte and Sectigo. |
| T1566.001 Spearphishing Attachment |
GroupTA505 | TA505 has used spearphishing emails with malicious attachments to initially compromise victims. |
| T1566.002 Spearphishing Link |
GroupTA505 | TA505 has sent spearphishing emails containing malicious links. |
| T1568.001 Fast Flux DNS |
GroupTA505 | TA505 has used fast flux to mask botnets by distributing payloads across multiple IPs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.