ATT&CKGroupsThreat Group-1314

Threat Group-1314

G0028

Threat group.View on attack.mitre.org

About this group

Threat Group-1314 is an unattributed threat group that has used compromised credentials to log into a victim's remote access infrastructure.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1021.002
SMB/Windows Admin Shares

Threat Group-1314 actors mapped network drives using net use.

T1059.003
Windows Command Shell

Threat Group-1314 actors spawned shells on remote systems on a victim network to execute commands.

T1072
Software Deployment Tools

Threat Group-1314 actors used a victim's endpoint management platform, Altiris, for lateral movement.

T1078.002
Domain Accounts

Threat Group-1314 actors used compromised domain credentials for the victim's endpoint management platform, Altiris, to move laterally.

Software2

Campaigns0

None recorded.

References1

  1. Dell TG-1314 Open source
    Dell SecureWorks Counter Threat Unit Special Operations Team. (2015, May 28). Living off the Land. Retrieved January 26, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.