ATT&CKReferencesCylance Cleaver

Cylance Cleaver

Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.

Open the source

Techniques2

Groups1

Software2

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupCleaver

Cleaver has been known to dump credentials using Mimikatz and Windows Credential Editor.

T1003.001
LSASS Memory
MalwareNet Crawler

Net Crawler uses credential dumpers such as Mimikatz and Windows Credential Editor to extract cached credentials from Windows systems.

T1021.002
SMB/Windows Admin Shares
MalwareNet Crawler

Net Crawler uses Windows admin shares to establish authenticated sessions to remote systems over SMB as part of lateral movement.

T1056.001
Keylogging
MalwareTinyZBot

TinyZBot contains keylogger functionality.

T1059.003
Windows Command Shell
MalwareTinyZBot

TinyZBot supports execution from the command-line.

T1110.002
Password Cracking
MalwareNet Crawler

Net Crawler uses a list of known credentials gathered through credential dumping to guess passwords to accounts as it spreads throughout a network.

T1113
Screen Capture
MalwareTinyZBot

TinyZBot contains screen capture functionality.

T1115
Clipboard Data
MalwareTinyZBot

TinyZBot contains functionality to collect information from the clipboard.

T1543.003
Windows Service
MalwareTinyZBot

TinyZBot can install as a Windows service for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareTinyZBot

TinyZBot can create a shortcut in the Windows startup folder for persistence.

T1547.009
Shortcut Modification
MalwareTinyZBot

TinyZBot can create a shortcut in the Windows startup folder for persistence.

T1557.002
ARP Cache Poisoning
GroupCleaver

Cleaver has used custom tools to facilitate ARP cache poisoning.

T1569.002
Service Execution
MalwareNet Crawler

Net Crawler uses PsExec to perform remote service manipulation to execute a copy of itself as part of lateral movement.

T1587.001
Malware
GroupCleaver

Cleaver has created customized tools and payloads for functions including ARP poisoning, encryption, credential dumping, ASP.NET shells, web backdoors, process enumeration, WMI querying, HTTP and SMB communications, network interface sniffing, and keystroke logging.

T1588.002
Tool
GroupCleaver

Cleaver has obtained and used open-source tools such as PsExec, Windows Credential Editor, and Mimikatz.

T1685
Disable or Modify Tools
MalwareTinyZBot

TinyZBot can disable Avira anti-virus.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.