Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAPT39 | APT39 has used Mimikatz, Windows Credential Editor and ProcDump to dump credentials. |
| T1018 Remote System Discovery |
GroupAPT39 | APT39 has used NBTscan and custom tools to discover remote systems. |
| T1021.001 Remote Desktop Protocol |
GroupAPT39 | APT39 has been seen using RDP for lateral movement and persistence, in some cases employing the rdpwinst tool for mangement of multiple sessions. |
| T1021.004 SSH |
GroupAPT39 | APT39 used secure shell (SSH) to move laterally among their targets. |
| T1027.002 Software Packing |
GroupAPT39 | APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection. |
| T1046 Network Service Discovery |
GroupAPT39 | APT39 has used CrackMapExec and a custom port scanner known as BLUETORCH for network scanning. |
| T1053.005 Scheduled Task |
GroupAPT39 | APT39 has created scheduled tasks for persistence. |
| T1059 Command and Scripting Interpreter |
GroupAPT39 | APT39 has utilized custom scripts to perform internal reconnaissance. |
| T1078 Valid Accounts |
GroupAPT39 | APT39 has used stolen credentials to compromise Outlook Web Access (OWA). |
| T1090.001 Internal Proxy |
GroupAPT39 | APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts. |
| T1110 Brute Force |
GroupAPT39 | APT39 has used Ncrack to reveal credentials. |
| T1204.001 Malicious Link |
GroupAPT39 | APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious link. |
| T1204.002 Malicious File |
GroupAPT39 | APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious attachment. |
| T1505.003 Web Shell |
GroupAPT39 | APT39 has installed ANTAK and ASPXSPY web shells. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT39 | APT39 has maintained persistence using the startup folder. |
| T1547.009 Shortcut Modification |
GroupAPT39 | APT39 has modified LNK shortcuts. |
| T1560.001 Archive via Utility |
GroupAPT39 | APT39 has used WinRAR and 7-Zip to compress an archive stolen data. |
| T1566.001 Spearphishing Attachment |
GroupAPT39 | APT39 leveraged spearphishing emails with malicious attachments to initially compromise victims. |
| T1566.002 Spearphishing Link |
GroupAPT39 | APT39 leveraged spearphishing emails with malicious links to initially compromise victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.