Cylance. (2014, December). Operation Cleaver. Retrieved September 14, 2017.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupCleaver | Cleaver has been known to dump credentials using Mimikatz and Windows Credential Editor. |
| T1003.001 LSASS Memory |
MalwareNet Crawler | Net Crawler uses credential dumpers such as Mimikatz and Windows Credential Editor to extract cached credentials from Windows systems. |
| T1021.002 SMB/Windows Admin Shares |
MalwareNet Crawler | Net Crawler uses Windows admin shares to establish authenticated sessions to remote systems over SMB as part of lateral movement. |
| T1056.001 Keylogging |
MalwareTinyZBot | TinyZBot contains keylogger functionality. |
| T1059.003 Windows Command Shell |
MalwareTinyZBot | TinyZBot supports execution from the command-line. |
| T1110.002 Password Cracking |
MalwareNet Crawler | Net Crawler uses a list of known credentials gathered through credential dumping to guess passwords to accounts as it spreads throughout a network. |
| T1113 Screen Capture |
MalwareTinyZBot | TinyZBot contains screen capture functionality. |
| T1115 Clipboard Data |
MalwareTinyZBot | TinyZBot contains functionality to collect information from the clipboard. |
| T1543.003 Windows Service |
MalwareTinyZBot | TinyZBot can install as a Windows service for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTinyZBot | TinyZBot can create a shortcut in the Windows startup folder for persistence. |
| T1547.009 Shortcut Modification |
MalwareTinyZBot | TinyZBot can create a shortcut in the Windows startup folder for persistence. |
| T1557.002 ARP Cache Poisoning |
GroupCleaver | Cleaver has used custom tools to facilitate ARP cache poisoning. |
| T1569.002 Service Execution |
MalwareNet Crawler | Net Crawler uses PsExec to perform remote service manipulation to execute a copy of itself as part of lateral movement. |
| T1587.001 Malware |
GroupCleaver | Cleaver has created customized tools and payloads for functions including ARP poisoning, encryption, credential dumping, ASP.NET shells, web backdoors, process enumeration, WMI querying, HTTP and SMB communications, network interface sniffing, and keystroke logging. |
| T1588.002 Tool |
GroupCleaver | Cleaver has obtained and used open-source tools such as PsExec, Windows Credential Editor, and Mimikatz. |
| T1685 Disable or Modify Tools |
MalwareTinyZBot | TinyZBot can disable Avira anti-virus. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.