Threat group.View on attack.mitre.org
Threat Group-1314 is an unattributed threat group that has used compromised credentials to log into a victim's remote access infrastructure.
| Technique | Procedure example |
|---|---|
| T1021.002 SMB/Windows Admin Shares |
Threat Group-1314 actors mapped network drives using |
| T1059.003 Windows Command Shell |
Threat Group-1314 actors spawned shells on remote systems on a victim network to execute commands. |
| T1072 Software Deployment Tools |
Threat Group-1314 actors used a victim's endpoint management platform, Altiris, for lateral movement. |
| T1078.002 Domain Accounts |
Threat Group-1314 actors used compromised domain credentials for the victim's endpoint management platform, Altiris, to move laterally. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.