Bohannon, D. & Carr N. (2017, June 30). Obfuscation in the Wild: Targeted Attackers Lead the Way in Evasion Techniques. Retrieved February 12, 2018.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
GroupFIN8 | FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads. |
| T1027.010 Command Obfuscation |
GroupFIN7 | FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands. |
| T1047 Windows Management Instrumentation |
GroupFIN8 | FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities. |
| T1059.001 PowerShell |
GroupFIN8 | FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access. |
| T1059.003 Windows Command Shell |
GroupFIN8 | FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`. |
| T1204.001 Malicious Link |
GroupFIN8 | FIN8 has used emails with malicious links to lure victims into installing malware. |
| T1204.002 Malicious File |
GroupFIN8 | FIN8 has used malicious e-mail attachments to lure victims into executing malware. |
| T1566.001 Spearphishing Attachment |
GroupFIN8 | FIN8 has distributed targeted emails containing Word documents with embedded malicious macros. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.