Ventura, V. (2021, September 16). Operation Layover: How we tracked an attack on the aviation industry to five years of compromise. Retrieved September 15, 2023.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016.001 Internet Connection Discovery |
GroupTA2541 | TA2541 has run scripts to check internet connectivity from compromised hosts. |
| T1027.002 Software Packing |
GroupTA2541 | TA2541 has used a .NET packer to obfuscate malicious files. |
| T1027.013 Encrypted/Encoded File |
GroupTA2541 | TA2541 has used compressed and char-encoded scripts in operations. |
| T1027.015 Compression |
GroupTA2541 | TA2541 has used compressed and char-encoded scripts in operations. |
| T1055 Process Injection |
GroupTA2541 | TA2541 has injected malicious code into legitimate .NET related processes including regsvcs.exe, msbuild.exe, and installutil.exe. |
| T1055.012 Process Hollowing |
GroupTA2541 | TA2541 has used process hollowing to execute CyberGate malware. |
| T1059.005 Visual Basic |
GroupTA2541 | TA2541 has used VBS files to execute or establish persistence for additional payloads, often using file names consistent with email themes or mimicking system functionality. |
| T1105 Ingress Tool Transfer |
GroupTA2541 | TA2541 has used malicious scripts and macros with the ability to download additional payloads. |
| T1204.002 Malicious File |
GroupTA2541 | TA2541 has used macro-enabled MS Word documents to lure victims into executing malicious payloads. |
| T1218.005 Mshta |
GroupTA2541 | TA2541 has used `mshta` to execute scripts including VBS. |
| T1566.001 Spearphishing Attachment |
GroupTA2541 | TA2541 has sent phishing emails with malicious attachments for initial access including MS Word documents. |
| T1573.002 Asymmetric Cryptography |
GroupTA2541 | TA2541 has used TLS encrypted C2 communications including for campaigns using AsyncRAT. |
| T1583.001 Domains |
GroupTA2541 | TA2541 has registered domains often containing the keywords “kimjoy,” “h0pe,” and “grace,” using domain registrars including Netdorm and No-IP DDNS, and hosting providers including xTom GmbH and Danilenko, Artyom. |
| T1588.002 Tool |
GroupTA2541 | TA2541 has used commodity remote access tools. |
| T1608.001 Upload Malware |
GroupTA2541 | TA2541 has uploaded malware to various platforms including Google Drive, Pastetext, Sharetext, and GitHub. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.