Security Response attack Investigation Team. (2019, March 27). Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.. Retrieved April 10, 2019.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials. |
| T1003.004 LSA Secrets |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1003.005 Cached Domain Credentials |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1040 Network Sniffing |
GroupAPT33 | APT33 has used SniffPass to collect credentials by sniffing network traffic. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupAPT33 | APT33 has used FTP to exfiltrate files (separately from the C2 channel). |
| T1053.005 Scheduled Task |
GroupAPT33 | APT33 has created a scheduled task to execute a .vbe file multiple times a day. |
| T1059.001 PowerShell |
GroupAPT33 | APT33 has utilized PowerShell to download files from the C2 server and run various scripts. |
| T1071.001 Web Protocols |
GroupAPT33 | APT33 has used HTTP for command and control. |
| T1105 Ingress Tool Transfer |
GroupAPT33 | APT33 has downloaded additional files and programs from its C2 server. |
| T1203 Exploitation for Client Execution |
GroupAPT33 | APT33 has attempted to exploit a known vulnerability in WinRAR (CVE-2018-20250), and attempted to gain remote code execution via a security bypass vulnerability (CVE-2017-11774). |
| T1204.001 Malicious Link |
GroupAPT33 | APT33 has lured users to click links to malicious HTML applications delivered via spearphishing emails. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT33 | APT33 has deployed a tool known as DarkComet to the Startup folder of a victim, and used Registry run keys to gain persistence. |
| T1552.001 Credentials In Files |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1552.006 Group Policy Preferences |
GroupAPT33 | APT33 has used a variety of publicly available tools like Gpppassword to gather credentials. |
| T1555 Credentials from Password Stores |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1555.003 Credentials from Web Browsers |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1560.001 Archive via Utility |
GroupAPT33 | APT33 has used WinRAR to compress data prior to exfil. |
| T1561.001 Disk Content Wipe |
MalwareStoneDrill | StoneDrill can wipe the accessible physical or logical drives of the infected machine. |
| T1561.002 Disk Structure Wipe |
MalwareStoneDrill | StoneDrill can wipe the master boot record of an infected computer. |
| T1566.002 Spearphishing Link |
GroupAPT33 | APT33 has sent spearphishing emails containing links to .hta files. |
| T1571 Non-Standard Port |
GroupAPT33 | APT33 has used HTTP over TCP ports 808 and 880 for command and control. |
| T1588.002 Tool |
GroupAPT33 | APT33 has obtained and leveraged publicly-available tools for early intrusion activities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.