ATT&CKReferencesFireEye APT39 Jan 2019

FireEye APT39 Jan 2019

Hawley et al. (2019, January 29). APT39: An Iranian Cyber Espionage Group Focused on Personal Information. Retrieved February 19, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT39

APT39 has used Mimikatz, Windows Credential Editor and ProcDump to dump credentials.

T1018
Remote System Discovery
GroupAPT39

APT39 has used NBTscan and custom tools to discover remote systems.

T1021.001
Remote Desktop Protocol
GroupAPT39

APT39 has been seen using RDP for lateral movement and persistence, in some cases employing the rdpwinst tool for mangement of multiple sessions.

T1021.004
SSH
GroupAPT39

APT39 used secure shell (SSH) to move laterally among their targets.

T1027.002
Software Packing
GroupAPT39

APT39 has packed tools with UPX, and has repacked a modified version of Mimikatz to thwart anti-virus detection.

T1046
Network Service Discovery
GroupAPT39

APT39 has used CrackMapExec and a custom port scanner known as BLUETORCH for network scanning.

T1053.005
Scheduled Task
GroupAPT39

APT39 has created scheduled tasks for persistence.

T1059
Command and Scripting Interpreter
GroupAPT39

APT39 has utilized custom scripts to perform internal reconnaissance.

T1078
Valid Accounts
GroupAPT39

APT39 has used stolen credentials to compromise Outlook Web Access (OWA).

T1090.001
Internal Proxy
GroupAPT39

APT39 used custom tools to create SOCK5 and custom protocol proxies between infected hosts.

T1110
Brute Force
GroupAPT39

APT39 has used Ncrack to reveal credentials.

T1204.001
Malicious Link
GroupAPT39

APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious link.

T1204.002
Malicious File
GroupAPT39

APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious attachment.

T1505.003
Web Shell
GroupAPT39

APT39 has installed ANTAK and ASPXSPY web shells.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT39

APT39 has maintained persistence using the startup folder.

T1547.009
Shortcut Modification
GroupAPT39

APT39 has modified LNK shortcuts.

T1560.001
Archive via Utility
GroupAPT39

APT39 has used WinRAR and 7-Zip to compress an archive stolen data.

T1566.001
Spearphishing Attachment
GroupAPT39

APT39 leveraged spearphishing emails with malicious attachments to initially compromise victims.

T1566.002
Spearphishing Link
GroupAPT39

APT39 leveraged spearphishing emails with malicious links to initially compromise victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.