Threat group.View on attack.mitre.org
Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
Windshift has used string encoding with floating point calculations. |
| T1033 System Owner/User Discovery |
Windshift has used malware to identify the username on a compromised host. |
| T1036 Masquerading |
Windshift has used icons mimicking MS Office files to mask malicious executables. Windshift has also attempted to hide executables by changing the file extension to ".scr" to mimic Windows screensavers. |
| T1036.001 Invalid Code Signature |
Windshift has used revoked certificates to sign malware. |
| T1047 Windows Management Instrumentation |
Windshift has used WMI to collect information about target machines. |
| T1057 Process Discovery |
Windshift has used malware to enumerate active processes. |
| T1059.005 Visual Basic |
Windshift has used Visual Basic 6 (VB6) payloads. |
| T1071.001 Web Protocols |
Windshift has used tools that communicate with C2 over HTTP. |
| T1082 System Information Discovery |
Windshift has used malware to identify the computer name of a compromised host. |
| T1105 Ingress Tool Transfer |
Windshift has used tools to deploy additional payloads to compromised hosts. |
| T1189 Drive-by Compromise |
Windshift has used compromised websites to register custom URL schemes on a remote system. |
| T1204.001 Malicious Link |
Windshift has used links embedded in e-mails to lure victims into executing malicious code. |
| T1204.002 Malicious File |
Windshift has used e-mail attachments to lure victims into executing malicious code. |
| T1518 Software Discovery |
Windshift has used malware to identify installed software. |
| T1518.001 Security Software Discovery |
Windshift has used malware to identify installed AV and commonly used forensic and malware analysis tools. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.