Axel F. (2017, April 27). APT Targets Financial Analysts with CVE-2017-0199. Retrieved February 15, 2018.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.002 Steganography |
MalwareZeroT | ZeroT has retrieved stage 2 payloads as Bitmap images that use Least Significant Bit (LSB) steganography. |
| T1059.001 PowerShell |
GroupTA459 | TA459 has used PowerShell for execution of a payload. |
| T1059.005 Visual Basic |
GroupTA459 | TA459 has a VBScript for execution. |
| T1071.001 Web Protocols |
MalwareZeroT | ZeroT has used HTTP for C2. |
| T1203 Exploitation for Client Execution |
GroupTA459 | TA459 has exploited Microsoft Word vulnerability CVE-2017-0199 for execution. |
| T1204.002 Malicious File |
GroupTA459 | TA459 has attempted to get victims to open malicious Microsoft Word attachment sent via spearphishing. |
| T1566.001 Spearphishing Attachment |
GroupTA459 | TA459 has targeted victims using spearphishing emails with malicious Microsoft Word attachments. |
| T1573.001 Symmetric Cryptography |
MalwareZeroT | ZeroT has used RC4 to encrypt C2 traffic. |
| T1574.001 DLL |
MalwareZeroT | ZeroT has used DLL side-loading to load malicious payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.