CISA. (2020, December 1). Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets. Retrieved December 9, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1078 Valid Accounts |
GroupDragonfly | Dragonfly has compromised user credentials and used valid accounts for operations. |
| T1083 File and Directory Discovery |
GroupDragonfly | Dragonfly has used a batch script to gather folder and file names from victim hosts. |
| T1110 Brute Force |
GroupDragonfly | Dragonfly has attempted to brute force credentials to gain access. |
| T1133 External Remote Services |
GroupDragonfly | Dragonfly has used VPNs and Outlook Web Access (OWA) to maintain access to victim networks. |
| T1190 Exploit Public-Facing Application |
GroupDragonfly | Dragonfly has conducted SQL injection attacks, exploited vulnerabilities CVE-2019-19781 and CVE-2020-0688 for Citrix and MS Exchange, and CVE-2018-13379 for Fortinet VPNs. |
| T1210 Exploitation of Remote Services |
GroupDragonfly | Dragonfly has exploited a Windows Netlogon vulnerability (CVE-2020-1472) to obtain access to Windows Active Directory servers. |
| T1583.001 Domains |
GroupDragonfly | Dragonfly has registered domains for targeting intended victims. |
| T1595.002 Vulnerability Scanning |
GroupDragonfly | Dragonfly has scanned targeted systems for vulnerable Citrix and Microsoft Exchange services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.