Raghuprasad, C . (2022, May 11). Bitter APT adds Bangladesh to their targets. Retrieved June 1, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareZxxZ | ZxxZ can collect data from a compromised host. |
| T1012 Query Registry |
MalwareZxxZ | ZxxZ can search the registry of a compromised host. |
| T1027.013 Encrypted/Encoded File |
MalwareZxxZ | ZxxZ has been encoded to avoid detection from static analysis tools. |
| T1033 System Owner/User Discovery |
MalwareZxxZ | ZxxZ can collect the username from a compromised host. |
| T1036.004 Masquerade Task or Service |
GroupBITTER | BITTER has disguised malware as a Windows Security update service. |
| T1036.004 Masquerade Task or Service |
MalwareZxxZ | ZxxZ has been disguised as a Windows security update service. |
| T1053.005 Scheduled Task |
GroupBITTER | BITTER has used scheduled tasks for persistence and execution. |
| T1053.005 Scheduled Task |
MalwareZxxZ | ZxxZ has used scheduled tasks for persistence and execution. |
| T1057 Process Discovery |
MalwareZxxZ | ZxxZ has created a snapshot of running processes using `CreateToolhelp32Snapshot`. |
| T1071.001 Web Protocols |
GroupBITTER | BITTER has used HTTP POST requests for C2. |
| T1082 System Information Discovery |
MalwareZxxZ | ZxxZ has collected the host name and operating system product name from a compromised machine. |
| T1105 Ingress Tool Transfer |
GroupBITTER | BITTER has downloaded additional malware and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareZxxZ | ZxxZ can download and execute additional files. |
| T1106 Native API |
MalwareZxxZ | ZxxZ has used API functions such as `Process32First`, `Process32Next`, and `ShellExecuteA`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareZxxZ | ZxxZ has used a XOR key to decrypt strings. |
| T1203 Exploitation for Client Execution |
GroupBITTER | BITTER has exploited Microsoft Office vulnerabilities CVE-2012-0158, CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802. |
| T1204.002 Malicious File |
MalwareZxxZ | ZxxZ has relied on victims to open a malicious attachment delivered via email. |
| T1204.002 Malicious File |
GroupBITTER | BITTER has attempted to lure victims into opening malicious attachments delivered via spearphishing. |
| T1518.001 Security Software Discovery |
MalwareZxxZ | ZxxZ can search a compromised host to determine if it is running Windows Defender or Kasperky antivirus. |
| T1559.002 Dynamic Data Exchange |
GroupBITTER | BITTER has executed OLE objects using Microsoft Equation Editor to download and run malicious payloads. |
| T1566.001 Spearphishing Attachment |
MalwareZxxZ | ZxxZ has been distributed via spearphishing emails, usually containing a malicious RTF or Excel attachment. |
| T1566.001 Spearphishing Attachment |
GroupBITTER | BITTER has sent spearphishing emails with a malicious RTF document or Excel spreadsheet. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.