Amnesty International. (2021, February 24). Vietnamese activists targeted by notorious hacking group. Retrieved March 1, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwareCobalt Strike | Cobalt Strike can track key presses with a keylogger module. |
| T1113 Screen Capture |
MalwareCobalt Strike | Cobalt Strike's Beacon payload is capable of capturing screenshots. |
| T1204.001 Malicious Link |
GroupAPT32 | APT32 has lured targets to download a Cobalt Strike beacon by including a malicious link within spearphishing emails. |
| T1204.001 Malicious Link |
MalwareKerrdown | Kerrdown has gained execution through victims opening malicious links. |
| T1204.002 Malicious File |
GroupAPT32 | APT32 has attempted to lure users to execute a malicious dropper delivered via a spearphishing attachment. |
| T1204.002 Malicious File |
MalwareKerrdown | Kerrdown has gained execution through victims opening malicious files. |
| T1566.001 Spearphishing Attachment |
MalwareKerrdown | Kerrdown has been distributed through malicious e-mail attachments. |
| T1566.001 Spearphishing Attachment |
GroupAPT32 | APT32 has sent spearphishing emails with a malicious executable disguised as a document or spreadsheet. |
| T1566.002 Spearphishing Link |
GroupAPT32 | APT32 has sent spearphishing emails containing malicious links. |
| T1566.002 Spearphishing Link |
MalwareKerrdown | Kerrdown has been distributed via e-mails containing a malicious link. |
| T1589 Gather Victim Identity Information |
GroupAPT32 | APT32 has conducted targeted surveillance against activists and bloggers. |
| T1589.002 Email Addresses |
GroupAPT32 | APT32 has collected e-mail addresses for activists and bloggers in order to target them with spyware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.