Symantec Security Response. (2017, November 7). Sowbug: Cyber espionage group targets South American and Southeast Asian governments. Retrieved November 16, 2017.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupSowbug | Sowbug has used credential dumping tools. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareStarloader | Starloader has masqueraded as legitimate software update packages such as Adobe Acrobat Reader and Intel. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSowbug | Sowbug named its tools to masquerade as Windows or Adobe Reader software, such as by using the file name adobecms.exe and the directory |
| T1039 Data from Network Shared Drive |
GroupSowbug | Sowbug extracted Word documents from a file server on a victim network. |
| T1056.001 Keylogging |
GroupSowbug | Sowbug has used keylogging tools. |
| T1059.003 Windows Command Shell |
GroupSowbug | Sowbug has used command line during its intrusions. |
| T1082 System Information Discovery |
GroupSowbug | Sowbug obtained OS version and hardware configuration from a victim. |
| T1083 File and Directory Discovery |
GroupSowbug | Sowbug identified and extracted all Word documents on a server by using a command containing * .doc and *.docx. The actors also searched for documents based on a specific date range and attempted to identify all installed software on a victim. |
| T1135 Network Share Discovery |
GroupSowbug | Sowbug listed remote shared drives that were accessible from a victim. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareStarloader | Starloader decrypts and executes shellcode from a file called Stars.jps. |
| T1560.001 Archive via Utility |
GroupSowbug | Sowbug extracted documents and bundled them into a RAR archive. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.