ATT&CKReferencesMicrosoft Holmium June 2020

Microsoft Holmium June 2020

Microsoft Threat Protection Intelligence Team. (2020, June 18). Inside Microsoft Threat Protection: Mapping attack chains from cloud to endpoint. Retrieved June 22, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1059.001
PowerShell
GroupAPT33

APT33 has utilized PowerShell to download files from the C2 server and run various scripts.

T1059.005
Visual Basic
GroupAPT33

APT33 has used VBScript to initiate the delivery of payloads.

T1078.004
Cloud Accounts
GroupAPT33

APT33 has used compromised Office 365 accounts in tandem with Ruler in an attempt to gain control of endpoints.

T1105
Ingress Tool Transfer
GroupAPT33

APT33 has downloaded additional files and programs from its C2 server.

T1110.003
Password Spraying
GroupAPT33

APT33 has used password spraying to gain access to target systems.

T1203
Exploitation for Client Execution
GroupAPT33

APT33 has attempted to exploit a known vulnerability in WinRAR (CVE-2018-20250), and attempted to gain remote code execution via a security bypass vulnerability (CVE-2017-11774).

T1204.002
Malicious File
GroupAPT33

APT33 has used malicious e-mail attachments to lure victims into executing malware.

T1546.003
Windows Management Instrumentation Event Subscription
GroupAPT33

APT33 has attempted to use WMI event subscriptions to establish persistence on compromised hosts.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT33

APT33 has deployed a tool known as DarkComet to the Startup folder of a victim, and used Registry run keys to gain persistence.

T1566.001
Spearphishing Attachment
GroupAPT33

APT33 has sent spearphishing e-mails with archive attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.