Weidemann, A. (2021, January 25). New campaign targeting security researchers. Retrieved December 20, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
GroupLazarus Group | Lazarus Group has used PowerShell to execute commands and malicious code. |
| T1105 Ingress Tool Transfer |
GroupLazarus Group | Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host. |
| T1189 Drive-by Compromise |
GroupLazarus Group | Lazarus Group delivered RATANKBA and other malicious code to victims via a compromised legitimate website. |
| T1566.003 Spearphishing via Service |
GroupLazarus Group | Lazarus Group has used social media platforms, including LinkedIn and Twitter, to send spearphishing messages. |
| T1583.001 Domains |
GroupLazarus Group | Lazarus Group has acquired domains related to their campaigns to act as distribution points and C2 channels. |
| T1585.001 Social Media Accounts |
GroupLazarus Group | Lazarus Group has created new Twitter accounts to conduct social engineering against potential victims. |
| T1587.001 Malware |
GroupLazarus Group | Lazarus Group has developed custom malware for use in their operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.