ATT&CKReferencesCylance Shaheen Nov 2018

Cylance Shaheen Nov 2018

Livelli, K, et al. (2018, November 12). Operation Shaheen. Retrieved May 1, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
MalwareRevenge RAT

Revenge RAT has a plugin for credential harvesting.

T1016
System Network Configuration Discovery
MalwareRevenge RAT

Revenge RAT collects the IP address and MAC address from the system.

T1021.001
Remote Desktop Protocol
MalwareRevenge RAT

Revenge RAT has a plugin to perform RDP access.

T1027.002
Software Packing
GroupThe White Company

The White Company has obfuscated their payloads through packing.

T1033
System Owner/User Discovery
MalwareRevenge RAT

Revenge RAT gathers the username from the system.

T1056.001
Keylogging
MalwareRevenge RAT

Revenge RAT has a plugin for keylogging.

T1070.004
File Deletion
GroupThe White Company

The White Company has the ability to delete its malware entirely from the target system.

T1082
System Information Discovery
MalwareRevenge RAT

Revenge RAT collects the CPU information, OS information, and system language.

T1105
Ingress Tool Transfer
MalwareRevenge RAT

Revenge RAT has the ability to upload and download files.

T1113
Screen Capture
MalwareRevenge RAT

Revenge RAT has a plugin for screen capture.

T1123
Audio Capture
MalwareRevenge RAT

Revenge RAT has a plugin for microphone interception.

T1124
System Time Discovery
GroupThe White Company

The White Company has checked the current date on the victim system.

T1125
Video Capture
MalwareRevenge RAT

Revenge RAT has the ability to access the webcam.

T1132.001
Standard Encoding
MalwareRevenge RAT

Revenge RAT uses Base64 to encode information sent to the C2 server.

T1203
Exploitation for Client Execution
GroupThe White Company

The White Company has taken advantage of a known vulnerability in Microsoft Word (CVE 2012-0158) to execute code.

T1204.002
Malicious File
GroupThe White Company

The White Company has used phishing lure documents that trick users into opening them and infecting their computers.

T1518.001
Security Software Discovery
GroupThe White Company

The White Company has checked for specific antivirus products on the target’s computer, including Kaspersky, Quick Heal, AVG, BitDefender, Avira, Sophos, Avast!, and ESET.

T1547.004
Winlogon Helper DLL
MalwareRevenge RAT

Revenge RAT creates a Registry key at HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell to survive a system reboot.

T1566.001
Spearphishing Attachment
GroupThe White Company

The White Company has sent phishing emails with malicious Microsoft Word attachments to victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.