Axiom

G0001

Threat group.View on attack.mitre.org

About this group

Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008. Some reporting suggests a degree of overlap between Axiom and Winnti Group but the two groups appear to be distinct based on differences in reporting on TTPs and targeting.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1001.002
Steganography

Axiom has used steganography to hide its C2 communications.

T1003
OS Credential Dumping

Axiom has been known to dump credentials.

T1005
Data from Local System

Axiom has collected data from a compromised network.

T1021.001
Remote Desktop Protocol

Axiom has used RDP during operations.

T1078
Valid Accounts

Axiom has used previously compromised administrative accounts to escalate privileges.

T1189
Drive-by Compromise

Axiom has used watering hole attacks to gain access.

T1190
Exploit Public-Facing Application

Axiom has been observed using SQL injection to gain access to systems.

T1203
Exploitation for Client Execution

Axiom has used exploits for multiple vulnerabilities including CVE-2014-0322, CVE-2012-4792, CVE-2012-1889, and CVE-2013-3893.

T1546.008
Accessibility Features

Axiom actors have been known to use the Sticky Keys replacement within RDP sessions to obtain persistence.

T1553
Subvert Trust Controls

Axiom has used digital certificates to deliver malware.

T1560
Archive Collected Data

Axiom has compressed and encrypted data prior to exfiltration.

T1563.002
RDP Hijacking

Axiom has targeted victims with remote administration tools including RDP.

T1566
Phishing

Axiom has used spear phishing to initially compromise victims.

T1583.002
DNS Server

Axiom has acquired dynamic DNS services for use in the targeting of intended victims.

T1583.003
Virtual Private Server

Axiom has used VPS hosting providers in targeting of intended victims.

View all 16 procedure examples

Software8

Campaigns0

None recorded.

References3

  1. Kaspersky Winnti April 2013 Open source
    Kaspersky Lab's Global Research and Analysis Team. (2013, April 11). Winnti. More than just a game. Retrieved February 8, 2017.
  2. Kaspersky Winnti June 2015 Open source
    Tarakanov, D. (2015, June 22). Games are over: Winnti is now targeting pharmaceutical companies. Retrieved January 14, 2016.
  3. Novetta Winnti April 2015 Open source
    Novetta Threat Research Group. (2015, April 7). Winnti Analysis. Retrieved February 8, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.