Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwareCHOPSTICK | CHOPSTICK is capable of performing keylogging. |
| T1059 Command and Scripting Interpreter |
MalwareCHOPSTICK | CHOPSTICK is capable of performing remote command execution. |
| T1059.003 Windows Command Shell |
MalwareXTunnel | XTunnel has been used to execute remote commands. |
| T1070.006 Timestomp |
GroupAPT28 | APT28 has performed timestomping on victim files. |
| T1090 Proxy |
MalwareXTunnel | XTunnel relays traffic between a C2 server and a victim. |
| T1105 Ingress Tool Transfer |
MalwareCHOPSTICK | CHOPSTICK is capable of performing remote file transmission. |
| T1218.011 Rundll32 |
GroupAPT28 | APT28 executed CHOPSTICK by using rundll32 commands such as |
| T1685.005 Clear Windows Event Logs |
GroupAPT28 | APT28 has cleared event logs, including by using the commands |
| T1685.005 Clear Windows Event Logs |
ToolWevtutil | Wevtutil can be used to clear system and security event logs from the system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.