ClearSky. (2020, February 16). Fox Kitten – Widespread Iranian Espionage-Offensive Campaign. Retrieved December 21, 2020.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1090.001 Internal Proxy |
MalwarePay2Key | Pay2Key has designated machines in the compromised network to serve as reverse proxy pivot points to channel communications with C2. |
| T1190 Exploit Public-Facing Application |
GroupFox Kitten | Fox Kitten has exploited known vulnerabilities in Fortinet, PulseSecure, and Palo Alto VPN appliances. |
| T1210 Exploitation of Remote Services |
GroupFox Kitten | Fox Kitten has exploited known vulnerabilities in remote services including RDP. |
| T1486 Data Encrypted for Impact |
MalwarePay2Key | Pay2Key can encrypt data on victim's machines using RSA and AES algorithms in order to extort a ransom payment for decryption. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.