ATT&CKReferencesNetscout Stolen Pencil Dec 2018

Netscout Stolen Pencil Dec 2018

ASERT team. (2018, December 5). STOLEN PENCIL Campaign Targets Academia. Retrieved February 5, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupKimsuky

Kimsuky has gathered credentials using Mimikatz and ProcDump.

T1021.001
Remote Desktop Protocol
GroupKimsuky

Kimsuky has used RDP for direct remote point-and-click access.

T1040
Network Sniffing
GroupKimsuky

Kimsuky has used the Nirsoft SniffPass network sniffer to obtain passwords sent over non-secure protocols.

T1056.001
Keylogging
GroupKimsuky

Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory.

T1078.003
Local Accounts
GroupKimsuky

Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP.

T1176.001
Browser Extensions
GroupKimsuky

Kimsuky has used Google Chrome browser extensions to infect victims and to steal passwords and cookies.

T1552.001
Credentials In Files
GroupKimsuky

Kimsuky has used tools that are capable of obtaining credentials from saved mail.

T1555.003
Credentials from Web Browsers
GroupKimsuky

Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers. Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims.

T1566.002
Spearphishing Link
GroupKimsuky

Kimsuky has sent spearphishing emails containing a link to a document that contained malicious macros or took the victim to an actor-controlled domain.

T1588.002
Tool
GroupKimsuky

Kimsuky has obtained and used tools such as Nirsoft WebBrowserPassVIew, Mimikatz, and PsExec.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.