ATT&CKReferencesMSTIC NOBELIUM May 2021

MSTIC NOBELIUM May 2021

Microsoft Threat Intelligence Center (MSTIC). (2021, May 27). New sophisticated email-based attack from NOBELIUM. Retrieved May 28, 2021.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1203
Exploitation for Client Execution
GroupAPT29

APT29 has used multiple software exploits for common client software, like Microsoft Word, Exchange, and Adobe Reader, to gain code execution.

T1204.001
Malicious Link
GroupAPT29

APT29 has used various forms of spearphishing attempting to get a user to click on a malicious link.

T1566.001
Spearphishing Attachment
GroupAPT29

APT29 has used spearphishing emails with an attachment to deliver files with exploits to initial victims.

T1566.002
Spearphishing Link
GroupAPT29

APT29 has used spearphishing with a link to trick victims into clicking on a link to a zip file containing malicious files.

T1566.003
Spearphishing via Service
GroupAPT29

APT29 has used the legitimate mailing service Constant Contact to send phishing e-mails.

T1583.006
Web Services
GroupAPT29

APT29 has registered algorithmically generated Twitter handles that are used for C2 by malware, such as HAMMERTOSS. APT29 has also used legitimate web services such as Dropbox and Constant Contact in their operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.