Salem, E. (2019, April 25). Threat Actor TA505 Targets Financial Enterprises Using LOLBins and a New Backdoor Malware. Retrieved May 28, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
GroupTA505 | TA505 has used base64 encoded PowerShell commands. |
| T1059.001 PowerShell |
GroupTA505 | TA505 has used PowerShell to download and execute malware and reconnaissance scripts. |
| T1105 Ingress Tool Transfer |
GroupTA505 | TA505 has downloaded additional malware to execute on victim systems. |
| T1204.001 Malicious Link |
GroupTA505 | TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1204.002 Malicious File |
GroupTA505 | TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1218.007 Msiexec |
GroupTA505 | TA505 has used |
| T1218.011 Rundll32 |
GroupTA505 | TA505 has leveraged |
| T1553.002 Code Signing |
GroupTA505 | TA505 has signed payloads with code signing certificates from Thawte and Sectigo. |
| T1566.001 Spearphishing Attachment |
GroupTA505 | TA505 has used spearphishing emails with malicious attachments to initially compromise victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.