ATT&CKReferencesSecureworks IRON TWILIGHT Active Measures March 2017

Secureworks IRON TWILIGHT Active Measures March 2017

Secureworks CTU. (2017, March 30). IRON TWILIGHT Supports Active Measures. Retrieved February 28, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1091
Replication Through Removable Media
MalwareCHOPSTICK

Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic.

T1113
Screen Capture
GroupAPT28

APT28 has used tools to take screenshots from victims.

T1189
Drive-by Compromise
GroupAPT28

APT28 has compromised targets via strategic web compromise utilizing custom exploit kits. APT28 used reflected cross-site scripting (XSS) against government websites to redirect users to phishing webpages.

T1204.001
Malicious Link
GroupAPT28

APT28 has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders.

T1204.002
Malicious File
GroupAPT28

APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts.

T1566.001
Spearphishing Attachment
GroupAPT28

APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments.

T1598
Phishing for Information
GroupAPT28

APT28 has used spearphishing to compromise credentials.

T1598.003
Spearphishing Link
GroupAPT28

APT28 has conducted credential phishing campaigns with links that redirect to credential harvesting sites.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.