Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
MalwarePowerShower | PowerShower is a backdoor written in PowerShell. |
| T1059.001 PowerShell |
GroupInception | Inception has used PowerShell to execute malicious commands and payloads. |
| T1059.005 Visual Basic |
GroupInception | Inception has used VBScript to execute malicious commands and payloads. |
| T1059.005 Visual Basic |
MalwarePowerShower | PowerShower has the ability to save and execute VBScript. |
| T1070.004 File Deletion |
MalwarePowerShower | PowerShower has the ability to remove all files created during the dropper process. |
| T1071.001 Web Protocols |
MalwarePowerShower | PowerShower has sent HTTP GET and POST requests to C2 servers to send information and receive instructions. |
| T1071.001 Web Protocols |
GroupInception | Inception has used HTTP, HTTPS, and WebDav in network communications. |
| T1082 System Information Discovery |
MalwarePowerShower | PowerShower has collected system information on the infected host. |
| T1112 Modify Registry |
MalwarePowerShower | PowerShower has added a registry key so future powershell.exe instances are spawned off-screen by default, and has removed all registry entries that are left behind during the dropper process. |
| T1132.001 Standard Encoding |
MalwarePowerShower | PowerShower has the ability to encode C2 communications with base64 encoding. |
| T1203 Exploitation for Client Execution |
GroupInception | Inception has exploited CVE-2012-0158, CVE-2014-1761, CVE-2017-11882 and CVE-2018-0802 for execution. |
| T1204.002 Malicious File |
GroupInception | Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware. |
| T1221 Template Injection |
GroupInception | Inception has used decoy documents to load malicious remote payloads via HTTP. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePowerShower | PowerShower sets up persistence with a Registry run key. |
| T1564.003 Hidden Window |
MalwarePowerShower | PowerShower has added a registry key so future powershell.exe instances are spawned with coordinates for a window position off-screen by default. |
| T1566.001 Spearphishing Attachment |
GroupInception | Inception has used weaponized documents attached to spearphishing emails for reconnaissance and initial compromise. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.