Unit42. (2016, May 1). Evasive Serpens Unit 42 Playbook Viewer. Retrieved February 6, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupOilRig | OilRig has used credential dumping tools such as Mimikatz to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.004 LSA Secrets |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1003.005 Cached Domain Credentials |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1021.001 Remote Desktop Protocol |
GroupOilRig | OilRig has used Remote Desktop Protocol for lateral movement. The group has also used tunneling tools to tunnel RDP into the environment. |
| T1021.004 SSH |
GroupOilRig | OilRig has used Putty to access compromised systems. |
| T1027.013 Encrypted/Encoded File |
GroupOilRig | OilRig has encrypted and encoded data in its malware, including by using base64. |
| T1071.001 Web Protocols |
GroupOilRig | OilRig has used HTTP for C2. |
| T1071.004 DNS |
GroupOilRig | OilRig has used DNS for C2 including the publicly available |
| T1078 Valid Accounts |
GroupOilRig | OilRig has used compromised credentials to access other systems on a victim network. |
| T1119 Automated Collection |
GroupOilRig | OilRig has used automated collection. |
| T1505.003 Web Shell |
GroupOilRig | OilRig has used web shells, often to maintain access to a victim network. |
| T1552.001 Credentials In Files |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1555 Credentials from Password Stores |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1555.003 Credentials from Web Browsers |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers. |
| T1572 Protocol Tunneling |
GroupOilRig | OilRig has used the Plink utility and other tools to create tunnels to C2 servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.