ATT&CKReferencesMandiant APT29 Trello

Mandiant APT29 Trello

Wolfram, J. et al. (2022, April 28). Trello From the Other Side: Tracking APT29 Phishing Campaigns. Retrieved August 3, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples1

TechniqueUsed byProcedure example
T1649
Steal or Forge Authentication Certificates
GroupAPT29

APT29 has abused misconfigured AD CS certificate templates to impersonate admin users and create additional authentication certificates.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.