ATT&CKReferencesAccenture MUDCARP March 2019

Accenture MUDCARP March 2019

Accenture iDefense Unit. (2019, March 5). Mudcarp's Focus on Submarine Technologies. Retrieved August 24, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareBADFLICK

BADFLICK has uploaded files from victims' machines.

T1016
System Network Configuration Discovery
MalwareBADFLICK

BADFLICK has captured victim IP address details.

T1055.001
Dynamic-link Library Injection
GroupLeviathan

Leviathan has utilized techniques like reflective DLL loading to write a DLL into memory and load a shell that provides backdoor access to the victim.

T1059.001
PowerShell
GroupLeviathan

Leviathan has used PowerShell for execution.

T1078
Valid Accounts
GroupLeviathan

Leviathan has obtained valid accounts to gain initial access.

T1082
System Information Discovery
MalwareBADFLICK

BADFLICK has captured victim computer name, memory space, and CPU details.

T1083
File and Directory Discovery
MalwareBADFLICK

BADFLICK has searched for files on the infected host.

T1105
Ingress Tool Transfer
MalwareBADFLICK

BADFLICK has download files from its C2 server.

T1140
Deobfuscate/Decode Files or Information
MalwareBADFLICK

BADFLICK can decode shellcode using a custom rotating XOR cipher.

T1203
Exploitation for Client Execution
GroupLeviathan

Leviathan has exploited multiple Microsoft Office and .NET vulnerabilities for execution, including CVE-2017-0199, CVE-2017-8759, and CVE-2017-11882.

T1204.002
Malicious File
MalwareBADFLICK

BADFLICK has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1497.003
Time Based Checks
MalwareBADFLICK

BADFLICK has delayed communication to the actor-controlled IP address by 5 minutes.

T1559.002
Dynamic Data Exchange
GroupLeviathan

Leviathan has utilized OLE as a method to insert malicious content inside various phishing documents.

T1560.002
Archive via Library
MalwareBADFLICK

BADFLICK has compressed data using the aPLib compression library.

T1566.001
Spearphishing Attachment
MalwareBADFLICK

BADFLICK has been distributed via spearphishing campaigns containing malicious Microsoft Word documents.

T1583.001
Domains
GroupLeviathan

Leviathan has established domains that impersonate legitimate entities to use for targeting efforts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.