ClearSky Research Team. (2020, August 1). The Kittens Are Back in Town 3 - Charming Kitten Campaign Evolved and Deploying Spear-Phishing link by WhatsApp. Retrieved April 21, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1189 Drive-by Compromise |
GroupMagic Hound | Magic Hound has conducted watering-hole attacks through media and magazine websites. |
| T1204.001 Malicious Link |
GroupMagic Hound | Magic Hound has attempted to lure victims into opening malicious links embedded in emails. |
| T1204.002 Malicious File |
GroupMagic Hound | Magic Hound has attempted to lure victims into opening malicious email attachments. |
| T1566.002 Spearphishing Link |
GroupMagic Hound | Magic Hound has sent malicious URL links through email to victims. In some cases the URLs were shortened or linked to Word documents with malicious macros that executed PowerShells scripts to download Pupy. |
| T1566.003 Spearphishing via Service |
GroupMagic Hound | Magic Hound used various social media channels (such as LinkedIn) as well as messaging services (such as WhatsApp) to spearphish victims. |
| T1584.001 Domains |
GroupMagic Hound | Magic Hound has used compromised domains to host links targeted to specific phishing victims. |
| T1585.001 Social Media Accounts |
GroupMagic Hound | Magic Hound has created fake LinkedIn and other social media accounts to contact targets and convince them--through messages and voice communications--to open malicious links. |
| T1598.003 Spearphishing Link |
GroupMagic Hound | Magic Hound has used SMS and email messages with links designed to steal credentials or track victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.