ATT&CKGroupsWindshift

Windshift

G0112

Threat group.View on attack.mitre.org

About this group

Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1027
Obfuscated Files or Information

Windshift has used string encoding with floating point calculations.

T1033
System Owner/User Discovery

Windshift has used malware to identify the username on a compromised host.

T1036
Masquerading

Windshift has used icons mimicking MS Office files to mask malicious executables. Windshift has also attempted to hide executables by changing the file extension to ".scr" to mimic Windows screensavers.

T1036.001
Invalid Code Signature

Windshift has used revoked certificates to sign malware.

T1047
Windows Management Instrumentation

Windshift has used WMI to collect information about target machines.

T1057
Process Discovery

Windshift has used malware to enumerate active processes.

T1059.005
Visual Basic

Windshift has used Visual Basic 6 (VB6) payloads.

T1071.001
Web Protocols

Windshift has used tools that communicate with C2 over HTTP.

T1082
System Information Discovery

Windshift has used malware to identify the computer name of a compromised host.

T1105
Ingress Tool Transfer

Windshift has used tools to deploy additional payloads to compromised hosts.

T1189
Drive-by Compromise

Windshift has used compromised websites to register custom URL schemes on a remote system.

T1204.001
Malicious Link

Windshift has used links embedded in e-mails to lure victims into executing malicious code.

T1204.002
Malicious File

Windshift has used e-mail attachments to lure victims into executing malicious code.

T1518
Software Discovery

Windshift has used malware to identify installed software.

T1518.001
Security Software Discovery

Windshift has used malware to identify installed AV and commonly used forensic and malware analysis tools.

View all 19 procedure examples

Software1

Campaigns0

None recorded.

References3

  1. SANS Windshift August 2018 Open source
    Karim, T. (2018, August). TRAILS OF WINDSHIFT. Retrieved November 17, 2024.
  2. objective-see windtail1 dec 2018 Open source
    Wardle, Patrick. (2018, December 20). Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 1). Retrieved October 3, 2019.
  3. objective-see windtail2 jan 2019 Open source
    Wardle, Patrick. (2019, January 15). Middle East Cyber-Espionage analyzing WindShift's implant: OSX.WindTail (part 2). Retrieved October 3, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.