Microsoft Threat Protection Intelligence Team. (2020, June 18). Inside Microsoft Threat Protection: Mapping attack chains from cloud to endpoint. Retrieved June 22, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
GroupAPT33 | APT33 has utilized PowerShell to download files from the C2 server and run various scripts. |
| T1059.005 Visual Basic |
GroupAPT33 | APT33 has used VBScript to initiate the delivery of payloads. |
| T1078.004 Cloud Accounts |
GroupAPT33 | APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints. |
| T1105 Ingress Tool Transfer |
GroupAPT33 | APT33 has downloaded additional files and programs from its C2 server. |
| T1110.003 Password Spraying |
GroupAPT33 | APT33 has used password spraying to gain access to target systems. |
| T1203 Exploitation for Client Execution |
GroupAPT33 | APT33 has attempted to exploit a known vulnerability in WinRAR (CVE-2018-20250), and attempted to gain remote code execution via a security bypass vulnerability (CVE-2017-11774). |
| T1204.002 Malicious File |
GroupAPT33 | APT33 has used malicious e-mail attachments to lure victims into executing malware. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupAPT33 | APT33 has attempted to use WMI event subscriptions to establish persistence on compromised hosts. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT33 | APT33 has deployed a tool known as DarkComet to the Startup folder of a victim, and used Registry run keys to gain persistence. |
| T1566.001 Spearphishing Attachment |
GroupAPT33 | APT33 has sent spearphishing e-mails with archive attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.