Unit 42. (2018, October 25). New Techniques to Uncover and Attribute Financial actors Commodity Builders and Infrastructure Revealed. Retrieved December 11, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
GroupCobalt Group | Cobalt Group has used a JavaScript backdoor that is capable of launching cmd.exe to execute shell commands. The group has used an exploit toolkit known as Threadkit that launches .bat files. |
| T1059.005 Visual Basic |
GroupCobalt Group | Cobalt Group has sent Word OLE compound documents with malicious obfuscated VBA macros that will run upon user execution. |
| T1059.007 JavaScript |
GroupCobalt Group | Cobalt Group has executed JavaScript scriptlets on the victim's machine. |
| T1204.001 Malicious Link |
GroupCobalt Group | Cobalt Group has sent emails containing malicious links that require users to execute a file or macro to infect the victim machine. |
| T1204.002 Malicious File |
GroupCobalt Group | Cobalt Group has sent emails containing malicious attachments that require users to execute a file or macro to infect the victim machine. |
| T1218.003 CMSTP |
GroupCobalt Group | Cobalt Group has used the command |
| T1566.001 Spearphishing Attachment |
GroupCobalt Group | Cobalt Group has sent spearphishing emails with various attachment types to corporate and personal email accounts of victim organizations. Attachment types have included .rtf, .doc, .xls, archives containing LNK files, and password protected archives containing .exe and .scr executables. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.