PwC and BAE Systems. (2017, April). Operation Cloud Hopper. Retrieved April 5, 2017.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
GroupmenuPass | menuPass has used RDP connections to move across the victim network. |
| T1021.004 SSH |
GroupmenuPass | menuPass has used Putty Secure Copy Client (PSCP) to transfer data. |
| T1039 Data from Network Shared Drive |
GroupmenuPass | menuPass has collected data from remote systems by mounting network shares with |
| T1049 System Network Connections Discovery |
GroupmenuPass | menuPass has used |
| T1059.003 Windows Command Shell |
GroupmenuPass | menuPass executes commands using a command-line interface and reverse shell. The group has used a modified version of pentesting script wmiexec.vbs to execute commands. menuPass has used malicious macros embedded inside Office documents to execute files. |
| T1074.001 Local Data Staging |
GroupmenuPass | menuPass stages data prior to exfiltration in multi-part archives, often saved in the Recycle Bin. |
| T1074.002 Remote Data Staging |
GroupmenuPass | menuPass has staged data on remote MSP systems or other victim networks prior to exfiltration. |
| T1078 Valid Accounts |
GroupmenuPass | menuPass has used valid accounts including shared between Managed Service Providers and clients to move between the two environments. |
| T1105 Ingress Tool Transfer |
GroupmenuPass | menuPass has installed updates and new malware on victims. |
| T1560.001 Archive via Utility |
GroupmenuPass | menuPass has compressed files before exfiltration using TAR and RAR. |
| T1574.001 DLL |
GroupmenuPass | menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT. menuPass has also used DLL search order hijacking. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.