ATT&CKReferencesSymantec Tick Apr 2016

Symantec Tick Apr 2016

DiMaggio, J. (2016, April 28). Tick cyberespionage group zeros in on Japan. Retrieved July 16, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareDaserf

Daserf leverages Mimikatz and Windows Credential Editor to steal credentials.

T1036.005
Match Legitimate Resource Name or Location
MalwareDaserf

Daserf uses file and folder names related to legitimate programs in order to blend in, such as HP, Intel, Adobe, and perflogs.

T1189
Drive-by Compromise
GroupBRONZE BUTLER

BRONZE BUTLER compromised three Japanese websites using a Flash exploit to perform watering hole attacks.

T1203
Exploitation for Client Execution
GroupBRONZE BUTLER

BRONZE BUTLER has exploited Microsoft Office vulnerabilities CVE-2014-4114, CVE-2018-0802, and CVE-2018-0798 for execution.

T1204.002
Malicious File
GroupBRONZE BUTLER

BRONZE BUTLER has attempted to get users to launch malicious Microsoft Word attachments delivered via spearphishing emails.

T1553.002
Code Signing
MalwareDaserf

Some Daserf samples were signed with a stolen digital certificate.

T1560
Archive Collected Data
MalwareDaserf

Daserf hides collected data in password-protected .rar archives.

T1560.001
Archive via Utility
MalwareDaserf

Daserf hides collected data in password-protected .rar archives.

T1566.001
Spearphishing Attachment
GroupBRONZE BUTLER

BRONZE BUTLER used spearphishing emails with malicious Microsoft Word attachments to infect victims.

T1588.002
Tool
GroupBRONZE BUTLER

BRONZE BUTLER has obtained and used open-source tools such as Mimikatz, gsecdump, and Windows Credential Editor.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.