Symantec Security Response. (2015, July 13). “Forkmeiamfamous”: Seaduke, latest weapon in the Duke armory. Retrieved July 22, 2015.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
MalwareSeaDuke | SeaDuke uses a module to execute Mimikatz with PowerShell to perform Pass the Ticket. |
| T1059.001 PowerShell |
GroupAPT29 | APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke. |
| T1059.006 Python |
GroupAPT29 | APT29 has developed malware variants written in Python. |
| T1070.004 File Deletion |
MalwareSeaDuke | SeaDuke can securely delete files, including deleting itself from the victim. |
| T1078 Valid Accounts |
MalwareSeaDuke | Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials. |
| T1114.002 Remote Email Collection |
MalwareSeaDuke | Some SeaDuke samples have a module to extract email from Microsoft Exchange servers using compromised credentials. |
| T1550.003 Pass the Ticket |
MalwareSeaDuke | Some SeaDuke samples have a module to use pass the ticket with Kerberos for authentication. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.