MSTIC. (2022, September 8). Microsoft investigates Iranian attacks against the Albanian government. Retrieved August 6, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
CampaignHomeLand Justice | During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment. |
| T1021.002 SMB/Windows Admin Shares |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used SMB for lateral movement. |
| T1027.013 Encrypted/Encoded File |
MalwareROADSWEEP | The ROADSWEEP binary contains RC4 encrypted embedded scripts. |
| T1046 Network Service Discovery |
CampaignHomeLand Justice | During HomeLand Justice, threat actors executed the Advanced Port Scanner tool on compromised systems. |
| T1047 Windows Management Instrumentation |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used WMI to modify Windows Defender settings. |
| T1059.001 PowerShell |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used PowerShell cmdlets New-MailboxSearch and Get-Recipient for discovery. |
| T1059.003 Windows Command Shell |
MalwareROADSWEEP | ROADSWEEP can open cmd.exe to enable command execution. |
| T1059.003 Windows Command Shell |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used Windows batch files for persistence and execution. |
| T1070.004 File Deletion |
MalwareROADSWEEP | ROADSWEEP can use embedded scripts to remove itself from the infected host. |
| T1078.001 Default Accounts |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used the built-in administrator account to move laterally using RDP and Impacket. |
| T1083 File and Directory Discovery |
MalwareROADSWEEP | ROADSWEEP can enumerate files on infected devices and avoid encrypting files with .exe, .dll, .sys, .lnk, or . lck extensions. |
| T1098.002 Additional Email Delegate Permissions |
CampaignHomeLand Justice | During HomeLand Justice, threat actors added the `ApplicationImpersonation` management role to accounts under their control to impersonate users and take ownership of targeted mailboxes. |
| T1105 Ingress Tool Transfer |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used web shells to download files to compromised infrastructure. |
| T1134.001 Token Impersonation/Theft |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used custom tooling to acquire tokens using `ImpersonateLoggedOnUser/SetThreadToken`. |
| T1480 Execution Guardrails |
MalwareROADSWEEP | ROADSWEEP requires four command line arguments to execute correctly, otherwise it will produce a message box and halt execution. |
| T1486 Data Encrypted for Impact |
MalwareROADSWEEP | ROADSWEEP can RC4 encrypt content in blocks on targeted systems. |
| T1486 Data Encrypted for Impact |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems. |
| T1491.001 Internal Defacement |
MalwareROADSWEEP | ROADSWEEP has dropped ransom notes in targeted folders prior to encrypting the files. |
| T1505.003 Web Shell |
CampaignHomeLand Justice | For HomeLand Justice, threat actors used .aspx webshells named pickers.aspx, error4.aspx, and ClientBin.aspx, to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareROADSWEEP | ROADSWEEP has been placed in the start up folder to trigger execution upon user login. |
| T1561.002 Disk Structure Wipe |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used a version of ZeroCleare to wipe disk drives on targeted hosts. |
| T1588.002 Tool |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used tools including Advanced Port Scanner, Mimikatz, and Impacket. |
| T1680 Local Storage Discovery |
MalwareROADSWEEP | ROADSWEEP can enumerate logical drives on targeted devices. |
| T1685 Disable or Modify Tools |
CampaignHomeLand Justice | During HomeLand Justice, threat actors modified and disabled components of endpoint detection and response (EDR) solutions including Microsoft Defender Antivirus. |
| T1685.001 Disable or Modify Windows Event Log |
CampaignHomeLand Justice | During HomeLand Justice, threat actors deleted Windows events and application logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.