APT18

G0026

Threat group.View on attack.mitre.org

About this group

APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

APT18 obfuscates strings in the payload.

T1053.002
At

APT18 actors used the native at Windows task scheduler tool to use scheduled tasks for execution on a victim network.

T1059.003
Windows Command Shell

APT18 uses cmd.exe to execute commands on the victim’s machine.

T1070.004
File Deletion

APT18 actors deleted tools and batch files from victim systems.

T1071.001
Web Protocols

APT18 uses HTTP for C2 communications.

T1071.004
DNS

APT18 uses DNS for C2 communications.

T1078
Valid Accounts

APT18 actors leverage legitimate credentials to log into external remote services.

T1082
System Information Discovery

APT18 can collect system information from the victim’s machine.

T1083
File and Directory Discovery

APT18 can list files information for specific directories.

T1105
Ingress Tool Transfer

APT18 can upload a file to the victim’s machine.

T1133
External Remote Services

APT18 actors leverage legitimate credentials to log into external remote services.

T1547.001
Registry Run Keys / Startup Folder

APT18 establishes persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key.

Software5

Campaigns0

None recorded.

References1

  1. Dell Lateral Movement Open source
    Carvey, H.. (2014, September 2). Where you AT?: Indicators of lateral movement using at.exe on Windows 7 systems. Retrieved January 25, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.