Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Tools Report. Retrieved March 10, 2016.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
GroupLazarus Group | Lazarus Group malware IndiaIndia obtains and sends to its C2 server the title of the window for each running process. The KilaAlfa keylogger also reports the title of the window in the foreground. |
| T1056.001 Keylogging |
GroupLazarus Group | Lazarus Group malware KiloAlfa contains keylogging functionality. |
| T1134.002 Create Process with Token |
GroupLazarus Group | Lazarus Group keylogger KiloAlfa obtains user tokens from interactive sessions to execute itself with API call |
| T1685 Disable or Modify Tools |
GroupLazarus Group | Lazarus Group malware TangoDelta attempts to terminate various processes associated with McAfee. Additionally, Lazarus Group malware SHARPKNOT disables the Microsoft Windows System Event Notification and Alerter services.. |
| T1686.003 Windows Host Firewall |
GroupLazarus Group | Various Lazarus Group malware modifies the Windows firewall to allow incoming connections or disable it entirely using netsh. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.