Microsoft Threat Intelligence. (2023, May 24). Volt Typhoon targets US critical infrastructure with living-off-the-land techniques. Retrieved July 27, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupVolt Typhoon | Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space. |
| T1003.003 NTDS |
GroupVolt Typhoon | Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes. |
| T1018 Remote System Discovery |
GroupVolt Typhoon | Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks. |
| T1047 Windows Management Instrumentation |
GroupVolt Typhoon | Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories. |
| T1057 Process Discovery |
GroupVolt Typhoon | Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist. |
| T1059.001 PowerShell |
GroupVolt Typhoon | Volt Typhoon has used PowerShell including for remote system discovery. |
| T1059.003 Windows Command Shell |
GroupVolt Typhoon | Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery. |
| T1074 Data Staged |
GroupVolt Typhoon | Volt Typhoon has staged collected data in password-protected archives. |
| T1078.002 Domain Accounts |
GroupVolt Typhoon | Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks. |
| T1090 Proxy |
GroupVolt Typhoon | Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic. |
| T1090.001 Internal Proxy |
GroupVolt Typhoon | Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access. |
| T1497.001 System Checks |
GroupVolt Typhoon | Volt Typhoon has run system checks to determine if they were operating in a virtualized environment. |
| T1584.008 Network Devices |
GroupVolt Typhoon | Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic. |
| T1588.002 Tool |
GroupVolt Typhoon | Volt Typhoon has used legitimate network and forensic tools and customized versions of open-source tools for C2. |
| T1680 Local Storage Discovery |
GroupVolt Typhoon | Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.