Campaign, Oct 2014 to Jan 2017.View on attack.mitre.org
C0032 was an extended campaign suspected to involve the Triton adversaries with related capabilities and techniques focused on gaining a foothold within IT environments. This campaign occurred in 2019 and was distinctly different from the Triton Safety Instrumented System Attack.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
During the C0032 campaign, TEMP.Veles used Mimikatz and a custom tool, SecHack, to harvest credentials. |
| T1021.001 Remote Desktop Protocol |
During the C0032 campaign, TEMP.Veles utilized RDP throughout an operation. |
| T1021.004 SSH |
During the C0032 campaign, TEMP.Veles relied on encrypted SSH-based tunnels to transfer tools and for remote command/program execution. |
| T1036.005 Match Legitimate Resource Name or Location |
During the C0032 campaign, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files. |
| T1053.005 Scheduled Task |
During the C0032 campaign, TEMP.Veles used scheduled task XML triggers. |
| T1059.001 PowerShell |
During the C0032 campaign, TEMP.Veles used PowerShell to perform timestomping. |
| T1070.004 File Deletion |
During the C0032 campaign, TEMP.Veles routinely deleted tools, logs, and other files after they were finished with them. |
| T1070.006 Timestomp |
During the C0032 campaign, TEMP.Veles used timestomping to modify the |
| T1074.001 Local Data Staging |
During the C0032 campaign, TEMP.Veles used staging folders that are infrequently used by legitimate users or processes to store data for exfiltration and tool deployment. |
| T1078 Valid Accounts |
During the C0032 campaign, TEMP.Veles used compromised VPN accounts. |
| T1133 External Remote Services |
During the C0032 campaign, TEMP.Veles used VPN access to persist in the victim environment. |
| T1505.003 Web Shell |
During the C0032 campaign, TEMP.Veles planted Web shells on Outlook Exchange servers. |
| T1546.012 Image File Execution Options Injection |
During the C0032 campaign, TEMP.Veles modified and added entries within |
| T1571 Non-Standard Port |
During the C0032 campaign, TEMP.Veles used port-protocol mismatches on ports such as 443, 4444, 8531, and 50501 during C2. |
| T1572 Protocol Tunneling |
During the C0032 campaign, TEMP.Veles used encrypted SSH-based PLINK tunnels to transfer tools and enable RDP connections throughout the environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.