Symantec Threat Hunter Team. (2019, September 18). Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks. Retrieved May 20, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
GroupCURIUM | CURIUM has leveraged PowerShell scripts for initial process execution and data gathering in victim environments. |
| T1082 System Information Discovery |
GroupCURIUM | CURIUM deploys information gathering tools focused on capturing IP configuration, running application, system information, and network connectivity information. |
| T1505.003 Web Shell |
GroupCURIUM | CURIUM has been linked to web shells following likely server compromise as an initial access vector into victim networks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.