ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareMilan | Milan can upload files from a compromised host. |
| T1005 Data from Local System |
MalwareShark | Shark can upload files to its C2. |
| T1008 Fallback Channels |
MalwareShark | Shark can update its configuration to use a different C2 server. |
| T1016 System Network Configuration Discovery |
MalwareMilan | Milan can run `C:\Windows\system32\cmd.exe /c cmd /c ipconfig /all 2>&1` to discover network settings. |
| T1021.005 VNC |
MalwareDanBot | DanBot can use VNC for remote access to targeted systems. |
| T1027.013 Encrypted/Encoded File |
MalwareShark | Shark can use encrypted and encoded files for C2 configuration. |
| T1027.013 Encrypted/Encoded File |
MalwareMilan | Milan can encode files containing information about the targeted system. |
| T1029 Scheduled Transfer |
MalwareShark | Shark can pause C2 communications for a specified time. |
| T1033 System Owner/User Discovery |
MalwareMilan | Milan can identify users registered to a targeted machine. |
| T1036 Masquerading |
MalwareMilan | Milan has used an executable named `companycatalogue` to appear benign. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareShark | Shark binaries have been named `audioddg.pdb` and `Winlangdb.pdb` in order to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDanBot | DanBot files have been named `UltraVNC.exe` and `WINVNC.exe` to appear as legitimate VNC tools. |
| T1036.007 Double File Extension |
MalwareMilan | Milan has used an executable named `companycatalog.exe.config` to appear benign. |
| T1041 Exfiltration Over C2 Channel |
MalwareShark | Shark has the ability to upload files from the compromised host over a DNS or HTTP C2 channel. |
| T1053.005 Scheduled Task |
MalwareMilan | Milan can establish persistence on a targeted host with scheduled tasks. |
| T1059.003 Windows Command Shell |
MalwareDanBot | DanBot has the ability to execute arbitrary commands via `cmd.exe`. |
| T1059.003 Windows Command Shell |
MalwareShark | Shark has the ability to use `CMD` to execute commands. |
| T1059.003 Windows Command Shell |
MalwareMilan | Milan can use `cmd.exe` for discovery actions on a targeted system. |
| T1070.004 File Deletion |
MalwareMilan | Milan can delete files via `C:\Windows\system32\cmd.exe /c ping 1.1.1.1 -n 1 -w 3000 > Nul & rmdir /s /q`. |
| T1070.004 File Deletion |
MalwareShark | Shark can delete files downloaded to the compromised host. |
| T1070.004 File Deletion |
MalwareDanBot | DanBot can delete its configuration file after installation. |
| T1071.001 Web Protocols |
MalwareShark | Shark has the ability to use HTTP in C2 communications. |
| T1071.001 Web Protocols |
MalwareMilan | Milan can use HTTPS for communication with C2. |
| T1071.004 DNS |
MalwareMilan | Milan has the ability to use DNS for C2 communications. |
| T1071.004 DNS |
MalwareShark | Shark can use DNS in C2 communications. |
| T1074 Data Staged |
MalwareShark | Shark has stored information in folders named `U1` and `U2` prior to exfiltration. |
| T1074.001 Local Data Staging |
MalwareMilan | Milan has saved files prior to upload from a compromised host to folders beginning with the characters `a9850d2f`. |
| T1082 System Information Discovery |
MalwareShark | Shark can collect the GUID of a targeted machine. |
| T1082 System Information Discovery |
MalwareMilan | Milan can enumerate the targeted machine's name and GUID. |
| T1087.001 Local Account |
MalwareMilan | Milan has run `C:\Windows\system32\cmd.exe /c cmd /c dir c:\users\ /s 2>&1` to discover local accounts. |
| T1105 Ingress Tool Transfer |
MalwareShark | Shark can download additional files from its C2 via HTTP or DNS. |
| T1105 Ingress Tool Transfer |
MalwareMilan | Milan has received files from C2 and stored them in log folders beginning with the character sequence `a9850d2f`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareShark | Shark can extract and decrypt downloaded .zip files. |
| T1204.002 Malicious File |
MalwareDanBot | DanBot has relied on victims' opening a malicious file for initial execution. |
| T1204.002 Malicious File |
GroupHEXANE | HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware. |
| T1497.001 System Checks |
MalwareShark | Shark can stop execution if the screen width of the targeted machine is not over 600 pixels. |
| T1559.001 Component Object Model |
MalwareMilan | Milan can use a COM component to generate scheduled tasks. |
| T1568.002 Domain Generation Algorithms |
MalwareShark | Shark can send DNS C2 communications using a unique domain generation algorithm. |
| T1583.001 Domains |
GroupHEXANE | HEXANE has registered and operated domains for campaigns, often using a security or web technology theme or impersonating the targeted organization. |
| T1585.001 Social Media Accounts |
GroupHEXANE | HEXANE has established fraudulent LinkedIn accounts impersonating HR department employees to target potential victims with fake job offers. |
| T1589 Gather Victim Identity Information |
GroupHEXANE | HEXANE has identified specific potential victims at targeted organizations. |
| T1589.002 Email Addresses |
GroupHEXANE | HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing. |
| T1591.004 Identify Roles |
GroupHEXANE | HEXANE has identified executives, HR, and IT staff at victim organizations for further targeting. |
| T1608.001 Upload Malware |
GroupHEXANE | HEXANE has staged malware on fraudulent websites set up to impersonate targeted organizations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.