Mandiant. (n.d.). APT42: Crooked Charms, Cons and Compromises. Retrieved October 9, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to collect network information. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT42 | APT42 has masqueraded the VINETHORN payload as a VPN application. |
| T1053.005 Scheduled Task |
GroupAPT42 | APT42 has used scheduled tasks for persistence. |
| T1056.001 Keylogging |
GroupAPT42 | APT42 has used custom malware to log keystrokes. |
| T1059.001 PowerShell |
GroupAPT42 | APT42 has downloaded and executed PowerShell payloads. |
| T1070.008 Clear Mailbox Data |
GroupAPT42 | APT42 has deleted login notification emails and has cleared the Sent folder to cover their tracks. |
| T1082 System Information Discovery |
GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to collect system information. |
| T1087.001 Local Account |
GroupAPT42 | APT42 has used the PowerShell-based POWERPOST script to collect local account names from the victim machine. |
| T1102 Web Service |
GroupAPT42 | APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations. |
| T1111 Multi-Factor Authentication Interception |
GroupAPT42 | APT42 has intercepted SMS-based one-time passwords and has set up two-factor authentication. Additionally, APT42 has used cloned or fake websites to capture MFA tokens. |
| T1112 Modify Registry |
GroupAPT42 | APT42 has modified Registry keys to maintain persistence. |
| T1113 Screen Capture |
GroupAPT42 | APT42 has used malware, such as GHAMBAR and POWERPOST, to take screenshots. |
| T1530 Data from Cloud Storage |
GroupAPT42 | APT42 has collected data from Microsoft 365 environments. |
| T1539 Steal Web Session Cookie |
GroupAPT42 | APT42 has used custom malware to steal login and cookie data from common browsers. |
| T1547 Boot or Logon Autostart Execution |
GroupAPT42 | APT42 has modified the Registry to maintain persistence. |
| T1555.003 Credentials from Web Browsers |
GroupAPT42 | APT42 has used custom malware to steal credentials. |
| T1566.002 Spearphishing Link |
GroupAPT42 | APT42 has sent spearphishing emails containing malicious links. |
| T1583.001 Domains |
GroupAPT42 | APT42 has registered domains, several of which masqueraded as news outlets and login services, for use in operations. |
| T1583.003 Virtual Private Server |
GroupAPT42 | APT42 has used anonymized infrastructure and Virtual Private Servers (VPSs) to interact with the victim’s environment. |
| T1608.001 Upload Malware |
GroupAPT42 | APT42 has used its infrastructure for C2 and for staging the VINETHORN payload, which masqueraded as a VPN application. |
| T1684.001 Impersonation |
GroupAPT42 | APT42 has impersonated legitimate people in phishing emails to gain credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.