ATT&CKReferencesMandiant APT42-untangling

Mandiant APT42-untangling

Rozmann, O., et al. (2024, May 1). Uncharmed: Untangling Iran's APT42 Operations. Retrieved October 9, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareTAMECAT

TAMECAT has used Windows Management Instrumentation (WMI) to query anti-virus products.

T1047
Windows Management Instrumentation
GroupAPT42

APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products.

T1056
Input Capture
GroupAPT42

APT42 has used credential harvesting websites.

T1059
Command and Scripting Interpreter
MalwareNICECURL

NICECURL has provided an arbitrary command execution interface.

T1059.001
PowerShell
MalwareTAMECAT

TAMECAT has used PowerShell to download and run additional content.

T1059.003
Windows Command Shell
MalwareTAMECAT

TAMECAT has used `cmd.exe` to run the `curl` command.

T1059.005
Visual Basic
MalwareTAMECAT

TAMECAT has used VBScript to query anti-virus products.

T1059.005
Visual Basic
GroupAPT42

APT42 has used a VBScript to query anti-virus products.

T1070
Indicator Removal
GroupAPT42

APT42 has cleared Chrome browser history.

T1070.004
File Deletion
MalwareNICECURL

NICECURL has a function to remove artifacts.

T1071.001
Web Protocols
MalwareTAMECAT

TAMECAT has used HTTP for C2 communications.

T1071.001
Web Protocols
MalwareNICECURL

NICECURL has used HTTPS for C2 communications.

T1071.001
Web Protocols
GroupAPT42

APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS.

T1102
Web Service
GroupAPT42

APT42 has used various links, such as links with typo-squatted domains, links to Dropbox files and links to fake Google sites, in spearphishing operations.

T1105
Ingress Tool Transfer
MalwareTAMECAT

TAMECAT has used `wget` and `curl` to download additional content.

T1105
Ingress Tool Transfer
MalwareNICECURL

NICECURL has the ability to download additional content onto an infected machine, e.g. by using `curl`.

T1111
Multi-Factor Authentication Interception
GroupAPT42

APT42 has intercepted SMS-based one-time passwords and has set up two-factor authentication. Additionally, APT42 has used cloned or fake websites to capture MFA tokens.

T1132.001
Standard Encoding
MalwareTAMECAT

TAMECAT has encoded C2 traffic with Base64.

T1132.001
Standard Encoding
GroupAPT42

APT42 has encoded C2 traffic with Base64.

T1518.001
Security Software Discovery
MalwareTAMECAT

TAMECAT has used Windows Management Instrumentation (WMI) to check for anti-virus products.

T1518.001
Security Software Discovery
GroupAPT42

APT42 has used Windows Management Instrumentation (WMI) to check for anti-virus products.

T1530
Data from Cloud Storage
GroupAPT42

APT42 has collected data from Microsoft 365 environments.

T1566.002
Spearphishing Link
GroupAPT42

APT42 has sent spearphishing emails containing malicious links.

T1573.001
Symmetric Cryptography
MalwareTAMECAT

TAMECAT has used AES to encrypt C2 traffic.

T1573.002
Asymmetric Cryptography
MalwareNICECURL

NICECURL has used HTTPS for C2 communications.

T1573.002
Asymmetric Cryptography
GroupAPT42

APT42 has used tools such as NICECURL with command and control communication taking place over HTTPS.

T1583.003
Virtual Private Server
GroupAPT42

APT42 has used anonymized infrastructure and Virtual Private Servers (VPSs) to interact with the victim’s environment.

T1588.002
Tool
GroupAPT42

APT42 has used built-in features in the Microsoft 365 environment and publicly available tools to avoid detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.