ESET. (2022, February). THREAT REPORT T3 2021. Retrieved February 10, 2022.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.006 HTML Smuggling |
GroupAPT29 | APT29 has embedded an ISO file within an HTML attachment that contained JavaScript code to initiate malware execution. |
| T1059.001 PowerShell |
GroupAPT29 | APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT29 | APT29 has exploited CVE-2021-36934 to escalate privileges on a compromised host. |
| T1204.002 Malicious File |
GroupAPT29 | APT29 has used various forms of spearphishing attempting to get a user to open attachments, including, but not limited to, malicious Microsoft Word documents, .pdf, and .lnk files. |
| T1218.005 Mshta |
GroupAPT29 | APT29 has use `mshta` to execute malicious scripts on a compromised host. |
| T1553.005 Mark-of-the-Web Bypass |
GroupAPT29 | APT29 has embedded ISO images and VHDX files in HTML to evade Mark-of-the-Web. |
| T1566.001 Spearphishing Attachment |
GroupAPT29 | APT29 has used spearphishing emails with an attachment to deliver files with exploits to initial victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.