Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
GroupTA2541 | TA2541 has used file names to mimic legitimate Windows files or system functionality. |
| T1047 Windows Management Instrumentation |
GroupTA2541 | TA2541 has used WMI to query targeted systems for security products. |
| T1053.005 Scheduled Task |
GroupTA2541 | TA2541 has used scheduled tasks to establish persistence for installed tools. |
| T1055 Process Injection |
GroupTA2541 | TA2541 has injected malicious code into legitimate .NET related processes including regsvcs.exe, msbuild.exe, and installutil.exe. |
| T1059.001 PowerShell |
GroupTA2541 | TA2541 has used PowerShell to download files and to inject into various Windows processes. |
| T1059.005 Visual Basic |
GroupTA2541 | TA2541 has used VBS files to execute or establish persistence for additional payloads, often using file names consistent with email themes or mimicking system functionality. |
| T1082 System Information Discovery |
GroupTA2541 | TA2541 has collected system information prior to downloading malware on the targeted host. |
| T1204.001 Malicious Link |
GroupTA2541 | TA2541 has used malicious links to cloud and web services to gain execution on victim machines. |
| T1204.002 Malicious File |
GroupTA2541 | TA2541 has used macro-enabled MS Word documents to lure victims into executing malicious payloads. |
| T1518.001 Security Software Discovery |
GroupTA2541 | TA2541 has used tools to search victim systems for security products such as antivirus and firewall software. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupTA2541 | TA2541 has placed VBS files in the Startup folder and used Registry run keys to establish persistence for malicious payloads. |
| T1566.001 Spearphishing Attachment |
GroupTA2541 | TA2541 has sent phishing emails with malicious attachments for initial access including MS Word documents. |
| T1566.002 Spearphishing Link |
GroupTA2541 | TA2541 has used spearphishing e-mails with malicious links to deliver malware. |
| T1568 Dynamic Resolution |
GroupTA2541 | TA2541 has used dynamic DNS services for C2 infrastructure. |
| T1583.001 Domains |
GroupTA2541 | TA2541 has registered domains often containing the keywords “kimjoy,” “h0pe,” and “grace,” using domain registrars including Netdorm and No-IP DDNS, and hosting providers including xTom GmbH and Danilenko, Artyom. |
| T1583.006 Web Services |
GroupTA2541 | TA2541 has hosted malicious files on various platforms including Google Drive, OneDrive, Discord, PasteText, ShareText, and GitHub. |
| T1588.001 Malware |
GroupTA2541 | TA2541 has used multiple strains of malware available for purchase on criminal forums or in open-source repositories. |
| T1608.001 Upload Malware |
GroupTA2541 | TA2541 has uploaded malware to various platforms including Google Drive, Pastetext, Sharetext, and GitHub. |
| T1685 Disable or Modify Tools |
GroupTA2541 | TA2541 has attempted to disable built-in security protections such as Windows AMSI. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.