Bash, A. (2021, October 14). Countering threats from Iran. Retrieved January 4, 2023.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1567 Exfiltration Over Web Service |
GroupMagic Hound | Magic Hound has used the Telegram API `sendMessage` to relay data on compromised devices. |
| T1584.001 Domains |
GroupMagic Hound | Magic Hound has used compromised domains to host links targeted to specific phishing victims. |
| T1589.002 Email Addresses |
GroupMagic Hound | Magic Hound has identified high-value email accounts in academia, journalism, NGO's, foreign policy, and national security for targeting. |
| T1590.005 IP Addresses |
GroupMagic Hound | Magic Hound has captured the IP addresses of visitors to their phishing sites. |
| T1591.001 Determine Physical Locations |
GroupMagic Hound | Magic Hound has collected location information from visitors to their phishing sites. |
| T1592.002 Software |
GroupMagic Hound | Magic Hound has captured the user-agent strings from visitors to their phishing sites. |
| T1598.003 Spearphishing Link |
GroupMagic Hound | Magic Hound has used SMS and email messages with links designed to steal credentials or track victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.