ATT&CKReferencesTrendMicro Tonto Team October 2020

TrendMicro Tonto Team October 2020

Daniel Lughi, Jaromir Horejsi. (2020, October 2). Tonto Team - Exploring the TTPs of an advanced threat actor operating a large infrastructure. Retrieved October 17, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupTonto Team

Tonto Team has used a variety of credential dumping tools.

T1056.001
Keylogging
GroupTonto Team

Tonto Team has used keylogging tools in their operations.

T1059.006
Python
GroupTonto Team

Tonto Team has used Python-based tools for execution.

T1068
Exploitation for Privilege Escalation
GroupTonto Team

Tonto Team has exploited CVE-2019-0803 and MS16-032 to escalate privileges.

T1069.001
Local Groups
GroupTonto Team

Tonto Team has used the ShowLocalGroupDetails command to identify administrator, user, and guest accounts on a compromised host.

T1090.002
External Proxy
GroupTonto Team

Tonto Team has routed their traffic through an external server in order to obfuscate their location.

T1135
Network Share Discovery
GroupTonto Team

Tonto Team has used tools such as NBTscan to enumerate network shares.

T1203
Exploitation for Client Execution
GroupTonto Team

Tonto Team has exploited Microsoft vulnerabilities, including CVE-2018-0798, CVE-2018-8174, CVE-2018-0802, CVE-2017-11882, CVE-2019-9489 CVE-2020-8468, and CVE-2018-0798 to enable execution of their delivered malicious payloads.

T1204.002
Malicious File
GroupTonto Team

Tonto Team has relied on user interaction to open their malicious RTF documents.

T1210
Exploitation of Remote Services
GroupTonto Team

Tonto Team has used EternalBlue exploits for lateral movement.

T1566.001
Spearphishing Attachment
GroupTonto Team

Tonto Team has delivered payloads via spearphishing attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.