ATT&CKReferencesSymantec Inception Framework March 2018

Symantec Inception Framework March 2018

Symantec. (2018, March 14). Inception Framework: Alive and Well, and Hiding Behind Proxies. Retrieved May 8, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1057
Process Discovery
GroupInception

Inception has used a reconnaissance module to identify active processes and other associated loaded modules.

T1069.002
Domain Groups
GroupInception

Inception has used specific malware modules to gather domain membership.

T1082
System Information Discovery
GroupInception

Inception has used a reconnaissance module to gather information about the operating system and hardware on the infected host.

T1083
File and Directory Discovery
GroupInception

Inception used a file listing plugin to collect information about file and directories both on local and remote drives.

T1090.003
Multi-hop Proxy
GroupInception

Inception used chains of compromised routers to proxy C2 communications between them and cloud service providers.

T1102
Web Service
GroupInception

Inception has incorporated at least five different cloud service providers into their C2 infrastructure including CloudMe.

T1203
Exploitation for Client Execution
GroupInception

Inception has exploited CVE-2012-0158, CVE-2014-1761, CVE-2017-11882 and CVE-2018-0802 for execution.

T1204.002
Malicious File
GroupInception

Inception lured victims into clicking malicious files for machine reconnaissance and to execute malware.

T1518
Software Discovery
GroupInception

Inception has enumerated installed software on compromised systems.

T1555.003
Credentials from Web Browsers
GroupInception

Inception used a browser plugin to steal passwords and sessions from Internet Explorer, Chrome, Opera, Firefox, Torch, and Yandex.

T1566.001
Spearphishing Attachment
GroupInception

Inception has used weaponized documents attached to spearphishing emails for reconnaissance and initial compromise.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.