ATT&CKReferencesSymantec Elderwood Sept 2012

Symantec Elderwood Sept 2012

O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.

Open the source

Techniques1

Groups1

Software9

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareHydraq

Hydraq uses basic obfuscation in the form of spaghetti code.

T1027.002
Software Packing
GroupElderwood

Elderwood has packed malware payloads before delivery to victims.

T1027.013
Encrypted/Encoded File
GroupElderwood

Elderwood has encrypted documents and malicious executables.

T1189
Drive-by Compromise
GroupElderwood

Elderwood has delivered zero-day exploits and malware to victims by injecting malicious code into specific public Web pages visited by targets within a particular sector.

T1203
Exploitation for Client Execution
GroupElderwood

Elderwood has used exploitation of endpoint software, including Microsoft Internet Explorer Adobe Flash vulnerabilities, to gain execution. They have also used zero-day exploits.

T1204.001
Malicious Link
GroupElderwood

Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open links.

T1204.002
Malicious File
GroupElderwood

Elderwood has leveraged multiple types of spearphishing in order to attempt to get a user to open attachments.

T1566.001
Spearphishing Attachment
GroupElderwood

Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing malicious attachments.

T1566.002
Spearphishing Link
GroupElderwood

Elderwood has delivered zero-day exploits and malware to victims via targeted emails containing a link to malicious content hosted on an uncommon Web server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.