Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
GroupConfucius | Confucius has used HTTP for C2 communications. |
| T1105 Ingress Tool Transfer |
GroupConfucius | Confucius has downloaded additional files and payloads onto a compromised host following initial access. |
| T1203 Exploitation for Client Execution |
GroupConfucius | Confucius has exploited Microsoft Office vulnerabilities, including CVE-2015-1641, CVE-2017-11882, and CVE-2018-0802. |
| T1204.002 Malicious File |
MalwareWarzoneRAT | WarzoneRAT has relied on a victim to open a malicious attachment within an email for execution. |
| T1204.002 Malicious File |
GroupConfucius | Confucius has lured victims to execute malicious attachments included in crafted spearphishing emails related to current topics. |
| T1221 Template Injection |
GroupConfucius | Confucius has used a weaponized Microsoft Word document with an embedded RTF exploit. |
| T1221 Template Injection |
MalwareWarzoneRAT | WarzoneRAT has been install via template injection through a malicious DLL embedded within a template RTF in a Word document. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupConfucius | Confucius has dropped malicious files into the startup folder `%AppData%\Microsoft\Windows\Start Menu\Programs\Startup` on a compromised host in order to maintain persistence. |
| T1566.001 Spearphishing Attachment |
MalwareWarzoneRAT | WarzoneRAT has been distributed as a malicious attachment within an email. |
| T1566.001 Spearphishing Attachment |
GroupConfucius | Confucius has crafted and sent victims malicious attachments to gain initial access. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.