Bermejo, L., et al. (2017, June 22). Following the Trail of BlackTech’s Cyber Espionage Campaigns. Retrieved May 5, 2020.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwarePLEAD | PLEAD samples were found to be highly obfuscated with junk code. |
| T1010 Application Window Discovery |
MalwarePLEAD | PLEAD has the ability to list open windows on the compromised host. |
| T1021 Remote Services |
MalwareKivars | Kivars has the ability to remotely trigger keyboard input and mouse clicks. |
| T1036.002 Right-to-Left Override |
GroupBlackTech | BlackTech has used right-to-left-override to obfuscate the filenames of malicious e-mail attachments. |
| T1056.001 Keylogging |
MalwareKivars | Kivars has the ability to initiate keylogging on the infected host. |
| T1057 Process Discovery |
MalwarePLEAD | PLEAD has the ability to list processes on the compromised host. |
| T1070.004 File Deletion |
MalwarePLEAD | PLEAD has the ability to delete files on the compromised host. |
| T1070.004 File Deletion |
MalwareKivars | Kivars has the ability to uninstall malware from the infected host. |
| T1071.001 Web Protocols |
MalwarePLEAD | PLEAD has used HTTP for communications with command and control (C2) servers. |
| T1083 File and Directory Discovery |
MalwarePLEAD | PLEAD has the ability to list drives and files on the compromised host. |
| T1083 File and Directory Discovery |
MalwareKivars | Kivars has the ability to list drives on the infected host. |
| T1105 Ingress Tool Transfer |
MalwareKivars | Kivars has the ability to download and execute files. |
| T1106 Native API |
MalwarePLEAD | PLEAD can use `ShellExecute` to execute applications. |
| T1113 Screen Capture |
MalwareKivars | Kivars has the ability to capture screenshots on the infected host. |
| T1190 Exploit Public-Facing Application |
GroupBlackTech | BlackTech has exploited a buffer overflow vulnerability in Microsoft Internet Information Services (IIS) 6.0, CVE-2017-7269, in order to establish a new HTTP or command and control (C2) server. |
| T1203 Exploitation for Client Execution |
GroupBlackTech | BlackTech has exploited multiple vulnerabilities for execution, including Microsoft Office vulnerabilities CVE-2012-0158, CVE-2014-6352, CVE-2017-0199, and Adobe Flash CVE-2015-5119. |
| T1204.001 Malicious Link |
MalwarePLEAD | PLEAD has been executed via malicious links in e-mails. |
| T1204.001 Malicious Link |
GroupBlackTech | BlackTech has used e-mails with malicious links to lure victims into installing malware. |
| T1204.002 Malicious File |
GroupBlackTech | BlackTech has used e-mails with malicious documents to lure victims into installing malware. |
| T1204.002 Malicious File |
MalwarePLEAD | PLEAD has been executed via malicious e-mail attachments. |
| T1555.003 Credentials from Web Browsers |
MalwarePLEAD | PLEAD can harvest saved credentials from browsers such as Google Chrome, Microsoft Internet Explorer, and Mozilla Firefox. |
| T1564.003 Hidden Window |
MalwareKivars | Kivars has the ability to conceal its activity through hiding active windows. |
| T1566.001 Spearphishing Attachment |
GroupBlackTech | BlackTech has used spearphishing e-mails with malicious password-protected archived files (ZIP or RAR) to deliver malware. |
| T1566.002 Spearphishing Link |
GroupBlackTech | BlackTech has used spearphishing e-mails with links to cloud services to deliver malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.