Hacquebord, F., Remorin, L. (2020, December 17). Pawn Storm’s Lack of Sophistication as a Strategy. Retrieved January 13, 2021.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
GroupAPT28 | APT28 has used tools to perform keylogging. |
| T1059.001 PowerShell |
GroupAPT28 | APT28 downloads and executes PowerShell scripts and performs PowerShell commands. |
| T1059.003 Windows Command Shell |
GroupAPT28 | An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads. |
| T1090.003 Multi-hop Proxy |
GroupAPT28 | APT28 has routed traffic over Tor and VPN servers to obfuscate their activities. |
| T1102.002 Bidirectional Communication |
GroupAPT28 | APT28 has used Google Drive for C2. |
| T1105 Ingress Tool Transfer |
GroupAPT28 | APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant. |
| T1110 Brute Force |
GroupAPT28 | APT28 can perform brute force attacks to obtain credentials. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT28 | APT28 has deployed malware that has copied itself to the startup directory for persistence. |
| T1566.001 Spearphishing Attachment |
GroupAPT28 | APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments. |
| T1567 Exfiltration Over Web Service |
GroupAPT28 | APT28 can exfiltrate data over Google Drive. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.