ATT&CKReferencesSymantec Tortoiseshell 2019

Symantec Tortoiseshell 2019

Symantec Threat Hunter Team. (2019, September 18). Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks. Retrieved May 20, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1059.001
PowerShell
GroupCURIUM

CURIUM has leveraged PowerShell scripts for initial process execution and data gathering in victim environments.

T1082
System Information Discovery
GroupCURIUM

CURIUM deploys information gathering tools focused on capturing IP configuration, running application, system information, and network connectivity information.

T1505.003
Web Shell
GroupCURIUM

CURIUM has been linked to web shells following likely server compromise as an initial access vector into victim networks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.