Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupFIN7 | FIN7 has collected files and other sensitive information from a compromised network. |
| T1021.001 Remote Desktop Protocol |
GroupFIN7 | FIN7 has used RDP to move laterally in victim environments. |
| T1021.004 SSH |
GroupFIN7 | FIN7 has used SSH to move laterally through victim environments. |
| T1021.005 VNC |
GroupFIN7 | FIN7 has used TightVNC to control compromised hosts. |
| T1027.010 Command Obfuscation |
GroupFIN7 | FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFIN7 | FIN7 has attempted to run Darkside ransomware with the filename sleep.exe. Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name. |
| T1053.005 Scheduled Task |
MalwareJSS Loader | JSS Loader has the ability to launch scheduled tasks to establish persistence. |
| T1059.001 PowerShell |
MalwareJSS Loader | JSS Loader has the ability to download and execute PowerShell scripts. |
| T1059.005 Visual Basic |
GroupFIN7 | FIN7 used VBS scripts to help perform tasks on the victim's machine. |
| T1059.005 Visual Basic |
MalwareJSS Loader | JSS Loader can download and execute VBScript files. |
| T1059.007 JavaScript |
MalwareJSS Loader | JSS Loader can download and execute JavaScript files. |
| T1078 Valid Accounts |
GroupFIN7 | FIN7 has harvested valid administrative credentials for lateral movement. |
| T1105 Ingress Tool Transfer |
MalwareJSS Loader | JSS Loader has the ability to download malicious executables to a compromised host. |
| T1204.001 Malicious Link |
GroupFIN7 | FIN7 has used malicious links to lure victims into downloading malware. |
| T1204.002 Malicious File |
GroupFIN7 | FIN7 lured victims to double-click on images in the attachments they sent which would then execute the hidden LNK file. Additionally, FIN7 has used malicious Microsoft Word and Excel files and Leo VBS to distribute an updated version of JSS Loader and to distribute the Harpy backdoor. |
| T1210 Exploitation of Remote Services |
GroupFIN7 | FIN7 has exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers. |
| T1486 Data Encrypted for Impact |
GroupFIN7 | FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting. |
| T1558.003 Kerberoasting |
GroupFIN7 | FIN7 has used Kerberoasting PowerShell commands such as, `Invoke-Kerberoast` for credential access and to enable lateral movement. |
| T1566.001 Spearphishing Attachment |
GroupFIN7 | FIN7 sent spearphishing emails with either malicious Microsoft Documents or RTF files attached. |
| T1566.002 Spearphishing Link |
GroupFIN7 | FIN7 has conducted broad phishing campaigns using malicious links. Additionally, FIN7 has sent spearphishing emails containing a typosquatted link to “ip-sccanner[.]com.” |
| T1567.002 Exfiltration to Cloud Storage |
GroupFIN7 | FIN7 has exfiltrated stolen data to the MEGA file sharing site. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.