ATT&CKReferencesMSTIC Octo Tempest Operations October 2023

MSTIC Octo Tempest Operations October 2023

Microsoft. (2023, October 25). Octo Tempest crosses boundaries to facilitate extortion, encryption, and destruction. Retrieved March 18, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupScattered Spider

Scattered Spider has extracted the `NTDS.dit` file by creating volume shadow copies of virtual domain controller disks.

T1006
Direct Volume Access
GroupScattered Spider

Scattered Spider has created volume shadow copies of virtual domain controller disks to extract the `NTDS.dit` file.

T1083
File and Directory Discovery
GroupScattered Spider

Scattered Spider Spider enumerates a target organization for files and directories of interest, including source code, user provisioning, MFA device registration, network diagrams, and shared credentials in documents or spreadsheets.

T1087.002
Domain Account
GroupScattered Spider

Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment.

T1098.003
Additional Cloud Roles
GroupScattered Spider

Scattered Spider has assigned user access admin roles in order to gain Tenant Root Group management permissions in Azure.

T1213.003
Code Repositories
GroupScattered Spider

Scattered Spider enumerates data stored within victim code repositories, such as internal GitHub repositories.

T1486
Data Encrypted for Impact
GroupScattered Spider

Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers.

T1556.009
Conditional Access Policies
GroupScattered Spider

Scattered Spider has added additional trusted locations to Azure AD conditional access policies.

T1564.008
Email Hiding Rules
GroupScattered Spider

Scattered Spider creates inbound rules on the compromised email accounts of security personnel to automatically delete emails from vendor security products.

T1567.002
Exfiltration to Cloud Storage
GroupScattered Spider

Scattered Spider has exfiltrated victim data to the MEGA file sharing site, SnowFlake, and AWS S3 buckets.

T1580
Cloud Infrastructure Discovery
GroupScattered Spider

Scattered Spider enumerates cloud environments including Amazon Web Services (AWS) S3 buckets to identify server and backup management infrastructure, resource access, databases and storage containers .

T1598.004
Spearphishing Voice
GroupScattered Spider

Scattered Spider has used help desk voice-based phishing and also called employees at target organizations and compelled them to navigate to fake login portals using adversary-in-the-middle toolkits.

T1684.001
Impersonation
GroupScattered Spider

Scattered Spider utilized social engineering to compel IT help desk personnel to reset passwords and MFA tokens. Scattered Spider has also used Microsoft Teams to pose as internal IT support or help desk personnel.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.