ATT&CKReferencesIBM ITG18 2020

IBM ITG18 2020

Wikoff, A. Emerson, R. (2020, July 16). New Research Exposes Iranian Threat Group Operations. Retrieved March 8, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1585.002
Email Accounts
GroupMagic Hound

Magic Hound has established email accounts using fake personas for spearphishing operations.

T1586.002
Email Accounts
GroupMagic Hound

Magic Hound has compromised personal email accounts through the use of legitimate credentials and gathered additional victim information.

T1589.001
Credentials
GroupMagic Hound

Magic Hound gathered credentials from two victims that they then attempted to validate across 75 different websites. Magic Hound has also collected credentials from over 900 Fortinet VPN servers in the US, Europe, and Israel.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.