Anthe, C. et al. (2015, October 19). Microsoft Security Intelligence Report Volume 19. Retrieved December 23, 2015.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1025 Data from Removable Media |
GroupAPT28 | An APT28 backdoor may collect the entire contents of an inserted USB device. |
| T1056.001 Keylogging |
GroupAPT28 | APT28 has used tools to perform keylogging. |
| T1068 Exploitation for Privilege Escalation |
GroupAPT28 | APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges. |
| T1071.001 Web Protocols |
MalwareCORESHELL | CORESHELL can communicate over HTTP for C2. |
| T1071.003 Mail Protocols |
MalwareCORESHELL | CORESHELL can communicate over SMTP and POP3 for C2. |
| T1074.001 Local Data Staging |
GroupAPT28 | APT28 has stored captured credential information in a file named pi.log. |
| T1091 Replication Through Removable Media |
GroupAPT28 | APT28 uses a tool to infect connected USB devices and transmit itself to air-gapped computers when the infected USB device is inserted. |
| T1091 Replication Through Removable Media |
MalwareCHOPSTICK | Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines and using files written to USB sticks to transfer data and command traffic. |
| T1092 Communication Through Removable Media |
MalwareCHOPSTICK | Part of APT28's operation involved using CHOPSTICK modules to copy itself to air-gapped machines, using files written to USB sticks to transfer data and command traffic. |
| T1092 Communication Through Removable Media |
GroupAPT28 | APT28 uses a tool that captures information from air-gapped computers via an infected USB and transfers it to network-connected computer when the USB is inserted. |
| T1120 Peripheral Device Discovery |
GroupAPT28 | APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. |
| T1211 Exploitation for Stealth |
GroupAPT28 | APT28 has used CVE-2015-4902 to bypass security features. |
| T1218.011 Rundll32 |
MalwareCORESHELL | CORESHELL is installed via execution of rundll32 with an export named "init" or "InitW." |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCORESHELL | CORESHELL has established persistence by creating autostart extensibility point (ASEP) Registry entries in the Run key and other Registry keys, as well as by creating shortcuts in the Internet Explorer Quick Start folder. |
| T1550.002 Pass the Hash |
GroupAPT28 | APT28 has used pass the hash for lateral movement. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.