Counter Threat Unit Research Team. (2019, September 11). COBALT DICKENS Goes Back to School…Again. Retrieved February 3, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1583.001 Domains |
GroupSilent Librarian | Silent Librarian has acquired domains to establish credential harvesting pages, often spoofing the target organization and using free top level domains .TK, .ML, .GA, .CF, and .GQ. |
| T1588.002 Tool |
GroupSilent Librarian | Silent Librarian has obtained free and publicly available tools including SingleFile and HTTrack to copy login pages of targeted organizations. |
| T1588.004 Digital Certificates |
GroupSilent Librarian | Silent Librarian has obtained free Let's Encrypt SSL certificates for use on their phishing pages. |
| T1598.003 Spearphishing Link |
GroupSilent Librarian | Silent Librarian has used links in e-mails to direct victims to credential harvesting websites designed to appear like the targeted organization's login page. |
| T1608.005 Link Target |
GroupSilent Librarian | Silent Librarian has cloned victim organization login pages and staged them for later use in credential harvesting campaigns. Silent Librarian has also made use of a variety of URL shorteners for these staged websites. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.