F-Secure Labs. (2015, September 17). The Dukes: 7 years of Russian cyberespionage. Retrieved December 10, 2015.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
MalwareOnionDuke | OnionDuke steals credentials from its victims. |
| T1003 OS Credential Dumping |
MalwarePinchDuke | PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated many sources such as WinInet Credential Cache, and Lightweight Directory Access Protocol (LDAP). |
| T1003.002 Security Account Manager |
MalwareCosmicDuke | CosmicDuke collects Windows account hashes. |
| T1003.004 LSA Secrets |
MalwareCosmicDuke | CosmicDuke collects LSA secrets. |
| T1005 Data from Local System |
MalwarePinchDuke | PinchDuke collects user files from the compromised host based on predefined file extensions. |
| T1007 System Service Discovery |
MalwareGeminiDuke | GeminiDuke collects information on programs and services on the victim that are configured to automatically run at startup. |
| T1016 System Network Configuration Discovery |
MalwareGeminiDuke | GeminiDuke collects information on network settings and Internet proxy settings from the victim. |
| T1056.001 Keylogging |
MalwareCosmicDuke | CosmicDuke uses a keylogger. |
| T1057 Process Discovery |
MalwareGeminiDuke | GeminiDuke collects information on running processes and environment variables from the victim. |
| T1068 Exploitation for Privilege Escalation |
MalwareCosmicDuke | CosmicDuke attempts to exploit privilege escalation vulnerabilities CVE-2010-0232 or CVE-2010-4398. |
| T1071.001 Web Protocols |
MalwareOnionDuke | OnionDuke uses HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareCloudDuke | One variant of CloudDuke uses HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareCosmicDuke | CosmicDuke can use HTTP or HTTPS for command and control to hard-coded C2 servers. |
| T1071.001 Web Protocols |
MalwareMiniDuke | MiniDuke uses HTTP and HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareGeminiDuke | GeminiDuke uses HTTP and HTTPS for command and control. |
| T1071.001 Web Protocols |
MalwareSeaDuke | SeaDuke uses HTTP and HTTPS for C2. |
| T1071.001 Web Protocols |
MalwarePinchDuke | PinchDuke transfers files from the compromised host via HTTP or HTTPS to a C2 server. |
| T1082 System Information Discovery |
MalwarePinchDuke | PinchDuke gathers system configuration information. |
| T1083 File and Directory Discovery |
MalwareGeminiDuke | GeminiDuke collects information from the victim, including installed drivers, programs previously executed by users, programs and services configured to automatically run at startup, files and folders present in any user's home folder, files and folders present in any user's My Documents, programs installed to the Program Files folder, and recently accessed files, folders, and programs. |
| T1083 File and Directory Discovery |
MalwarePinchDuke | PinchDuke searches for files created within a certain timeframe and whose file extension matches a predefined list. |
| T1087.001 Local Account |
MalwareGeminiDuke | GeminiDuke collects information on local user accounts from the victim. |
| T1102.001 Dead Drop Resolver |
MalwareMiniDuke | Some MiniDuke components use Twitter to initially obtain the address of a C2 server or as a backup if no hard-coded C2 server responds. |
| T1102.002 Bidirectional Communication |
MalwareCloudDuke | One variant of CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data with its operators. |
| T1102.003 One-Way Communication |
MalwareOnionDuke | OnionDuke uses Twitter as a backup C2. |
| T1105 Ingress Tool Transfer |
GroupAPT29 | APT29 has downloaded additional tools and malware onto compromised networks. |
| T1105 Ingress Tool Transfer |
MalwareCloudDuke | CloudDuke downloads and executes additional malware from either a Web address or a Microsoft OneDrive account. |
| T1203 Exploitation for Client Execution |
GroupAPT29 | APT29 has used multiple software exploits for common client software, like Microsoft Word, Exchange, and Adobe Reader, to gain code execution. |
| T1204.002 Malicious File |
GroupAPT29 | APT29 has used various forms of spearphishing attempting to get a user to open attachments, including, but not limited to, malicious Microsoft Word documents, .pdf, and .lnk files. |
| T1555 Credentials from Password Stores |
MalwarePinchDuke | PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as The Bat!, Yahoo!, Mail.ru, Passport.Net, Google Talk, and Microsoft Outlook. |
| T1555 Credentials from Password Stores |
MalwareCosmicDuke | CosmicDuke collects user credentials, including passwords, for various programs including popular instant messaging applications and email clients as well as WLAN keys. |
| T1555.003 Credentials from Web Browsers |
MalwarePinchDuke | PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as Netscape Navigator, Mozilla Firefox, Mozilla Thunderbird, and Internet Explorer. |
| T1555.003 Credentials from Web Browsers |
MalwareCosmicDuke | CosmicDuke collects user credentials, including passwords, for various programs including Web browsers. |
| T1566.001 Spearphishing Attachment |
GroupAPT29 | APT29 has used spearphishing emails with an attachment to deliver files with exploits to initial victims. |
| T1587.001 Malware |
GroupAPT29 | APT29 has used unique malware in many of their operations. |
| T1588.002 Tool |
GroupAPT29 | APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.