Daniel Lughi, Jaromir Horejsi. (2020, October 2). Tonto Team - Exploring the TTPs of an advanced threat actor operating a large infrastructure. Retrieved October 17, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupTonto Team | Tonto Team has used a variety of credential dumping tools. |
| T1056.001 Keylogging |
GroupTonto Team | Tonto Team has used keylogging tools in their operations. |
| T1059.006 Python |
GroupTonto Team | Tonto Team has used Python-based tools for execution. |
| T1068 Exploitation for Privilege Escalation |
GroupTonto Team | Tonto Team has exploited CVE-2019-0803 and MS16-032 to escalate privileges. |
| T1069.001 Local Groups |
GroupTonto Team | Tonto Team has used the |
| T1090.002 External Proxy |
GroupTonto Team | Tonto Team has routed their traffic through an external server in order to obfuscate their location. |
| T1135 Network Share Discovery |
GroupTonto Team | Tonto Team has used tools such as NBTscan to enumerate network shares. |
| T1203 Exploitation for Client Execution |
GroupTonto Team | Tonto Team has exploited Microsoft vulnerabilities, including CVE-2018-0798, CVE-2018-8174, CVE-2018-0802, CVE-2017-11882, CVE-2019-9489 CVE-2020-8468, and CVE-2018-0798 to enable execution of their delivered malicious payloads. |
| T1204.002 Malicious File |
GroupTonto Team | Tonto Team has relied on user interaction to open their malicious RTF documents. |
| T1210 Exploitation of Remote Services |
GroupTonto Team | Tonto Team has used EternalBlue exploits for lateral movement. |
| T1566.001 Spearphishing Attachment |
GroupTonto Team | Tonto Team has delivered payloads via spearphishing attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.