Grunzweig, J., Lee, B. (2016, January 22). New Attacks Linked to C0d0so0 Group. Retrieved August 2, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupAPT19 | APT19 used an HTTP malware variant and a Port 22 malware variant to collect the MAC address and IP address from the victim’s machine. |
| T1033 System Owner/User Discovery |
GroupAPT19 | APT19 used an HTTP malware variant and a Port 22 malware variant to collect the victim’s username. |
| T1071.001 Web Protocols |
GroupAPT19 | APT19 used HTTP for C2 communications. APT19 also used an HTTP malware variant to communicate over HTTP for C2. |
| T1082 System Information Discovery |
GroupAPT19 | APT19 collected system architecture information. APT19 used an HTTP malware variant and a Port 22 malware variant to gather the hostname and CPU information from the victim’s machine. |
| T1112 Modify Registry |
GroupAPT19 | APT19 uses a Port 22 malware variant to modify several Registry keys. |
| T1132.001 Standard Encoding |
GroupAPT19 | An APT19 HTTP malware variant used Base64 to encode communications to the C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT19 | An APT19 HTTP malware variant decrypts strings using single-byte XOR keys. |
| T1189 Drive-by Compromise |
GroupAPT19 | APT19 performed a watering hole attack on forbes.com in 2014 to compromise targets. |
| T1543.003 Windows Service |
GroupAPT19 | An APT19 Port 22 malware variant registers itself as a service. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT19 | An APT19 HTTP malware variant establishes persistence by setting the Registry key |
| T1574.001 DLL |
GroupAPT19 | APT19 launched an HTTP malware variant and a Port 22 malware variant using a legitimate executable that loaded the malicious DLL. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.