Threat group.View on attack.mitre.org
APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
APT18 obfuscates strings in the payload. |
| T1053.002 At |
APT18 actors used the native at Windows task scheduler tool to use scheduled tasks for execution on a victim network. |
| T1059.003 Windows Command Shell |
APT18 uses cmd.exe to execute commands on the victim’s machine. |
| T1070.004 File Deletion |
APT18 actors deleted tools and batch files from victim systems. |
| T1071.001 Web Protocols |
APT18 uses HTTP for C2 communications. |
| T1071.004 DNS |
APT18 uses DNS for C2 communications. |
| T1078 Valid Accounts |
APT18 actors leverage legitimate credentials to log into external remote services. |
| T1082 System Information Discovery |
APT18 can collect system information from the victim’s machine. |
| T1083 File and Directory Discovery |
APT18 can list files information for specific directories. |
| T1105 Ingress Tool Transfer |
APT18 can upload a file to the victim’s machine. |
| T1133 External Remote Services |
APT18 actors leverage legitimate credentials to log into external remote services. |
| T1547.001 Registry Run Keys / Startup Folder |
APT18 establishes persistence via the |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.