ATT&CKReferencesSecureworks IRON HEMLOCK Profile

Secureworks IRON HEMLOCK Profile

Secureworks CTU. (n.d.). IRON HEMLOCK. Retrieved February 22, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1059.001
PowerShell
GroupAPT29

APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke.

T1204.002
Malicious File
GroupAPT29

APT29 has used various forms of spearphishing attempting to get a user to open attachments, including, but not limited to, malicious Microsoft Word documents, .pdf, and .lnk files.

T1566.001
Spearphishing Attachment
GroupAPT29

APT29 has used spearphishing emails with an attachment to deliver files with exploits to initial victims.

T1573
Encrypted Channel
GroupAPT29

APT29 has used multiple layers of encryption within malware to protect C2 communication.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.