ASERT team. (2018, December 5). STOLEN PENCIL Campaign Targets Academia. Retrieved February 5, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupKimsuky | Kimsuky has gathered credentials using Mimikatz and ProcDump. |
| T1021.001 Remote Desktop Protocol |
GroupKimsuky | Kimsuky has used RDP for direct remote point-and-click access. |
| T1040 Network Sniffing |
GroupKimsuky | Kimsuky has used the Nirsoft SniffPass network sniffer to obtain passwords sent over non-secure protocols. |
| T1056.001 Keylogging |
GroupKimsuky | Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory. |
| T1078.003 Local Accounts |
GroupKimsuky | Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP. |
| T1176.001 Browser Extensions |
GroupKimsuky | Kimsuky has used Google Chrome browser extensions to infect victims and to steal passwords and cookies. |
| T1552.001 Credentials In Files |
GroupKimsuky | Kimsuky has used tools that are capable of obtaining credentials from saved mail. |
| T1555.003 Credentials from Web Browsers |
GroupKimsuky | Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers. Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims. |
| T1566.002 Spearphishing Link |
GroupKimsuky | Kimsuky has sent spearphishing emails containing a link to a document that contained malicious macros or took the victim to an actor-controlled domain. |
| T1588.002 Tool |
GroupKimsuky | Kimsuky has obtained and used tools such as Nirsoft WebBrowserPassVIew, Mimikatz, and PsExec. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.