Ahn Ho, Facundo Muñoz, & Marc-Etienne M.Léveillé. (2024, March 7). Evasive Panda leverages Monlam Festival to target Tibetans. Retrieved July 25, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareNightdoor | Nightdoor gathers information on victim system network configuration such as MAC addresses. |
| T1033 System Owner/User Discovery |
MalwareNightdoor | Nightdoor gathers information on victim system users and usernames. |
| T1053.005 Scheduled Task |
GroupDaggerfly | Daggerfly has attempted to use scheduled tasks for persistence in victim environments. |
| T1057 Process Discovery |
MalwareNightdoor | Nightdoor can collect information on installed applications via Windows registry keys, as well as collecting information on running processes. |
| T1070.004 File Deletion |
MalwareNightdoor | Nightdoor can self-delete. |
| T1071 Application Layer Protocol |
MalwareNightdoor | Nightdoor uses TCP and UDP communication for command and control traffic. |
| T1071.001 Web Protocols |
GroupDaggerfly | Daggerfly uses HTTP for command and control communication. |
| T1082 System Information Discovery |
MalwareNightdoor | Nightdoor gathers information on the victim system such as CPU and Computer name as well as device drivers. |
| T1082 System Information Discovery |
GroupDaggerfly | Daggerfly utilizes victim machine operating system information to create custom User Agent strings for subsequent command and control communication. |
| T1102 Web Service |
MalwareNightdoor | Nightdoor can utilize Microsoft OneDrive or Google Drive for command and control purposes. |
| T1124 System Time Discovery |
MalwareNightdoor | Nightdoor can identify the system local time information. |
| T1189 Drive-by Compromise |
GroupDaggerfly | Daggerfly has used strategic website compromise for initial access against victims. |
| T1195.002 Compromise Software Supply Chain |
GroupDaggerfly | Daggerfly is associated with several supply chain compromises using malicious updates to compromise victims. |
| T1204.001 Malicious Link |
GroupDaggerfly | Daggerfly has used strategic website compromise to deliver a malicious link requiring user interaction. |
| T1553.002 Code Signing |
GroupDaggerfly | Daggerfly has used signed, but not notarized, malicious files for execution in macOS environments. |
| T1574.001 DLL |
GroupDaggerfly | Daggerfly has used legitimate software to side-load PlugX loaders onto victim systems. Daggerfly is also linked to multiple other instances of side-loading for initial loading activity. |
| T1584.004 Server |
GroupDaggerfly | Daggerfly compromised web servers hosting updates for software as part of a supply chain intrusion. |
| T1587.002 Code Signing Certificates |
GroupDaggerfly | Daggerfly created code signing certificates to sign malicious macOS files. |
| T1680 Local Storage Discovery |
MalwareNightdoor | Nightdoor can collect information about disk drives, their total and free space, and file system type. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.