O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareHydraq | Hydraq uses basic obfuscation in the form of spaghetti code. |
| T1027.002 Software Packing |
GroupElderwood | Elderwood has packed malware payloads before delivery to victims. |
| T1027.013 Encrypted/Encoded File |
GroupElderwood | Elderwood has encrypted documents and malicious executables. |
| T1189 Drive-by Compromise |
GroupElderwood | Elderwood has delivered zero-day exploits and malware to victims by injecting malicious code into specific public Web pages visited by targets within a particular sector. |
| T1203 Exploitation for Client Execution |
GroupElderwood | Elderwood has used exploitation of endpoint software, including Microsoft Internet Explorer Adobe Flash vulnerabilities, to gain execution. They have also used zero-day exploits. |
| T1204.001 Malicious Link |
GroupElderwood | Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open links. |
| T1204.002 Malicious File |
GroupElderwood | Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open attachments. |
| T1566.001 Spearphishing Attachment |
GroupElderwood | Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing malicious attachments. |
| T1566.002 Spearphishing Link |
GroupElderwood | Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing a link to malicious content hosted on an uncommon Web server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.