ATT&CKReferencesNovetta-Axiom

Novetta-Axiom

Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples29

TechniqueUsed byProcedure example
T1001.002
Steganography
GroupAxiom

Axiom has used steganography to hide its C2 communications.

T1001.002
Steganography
MalwareZox

Zox has used the .PNG file format for C2 communications.

T1003
OS Credential Dumping
GroupAxiom

Axiom has been known to dump credentials.

T1005
Data from Local System
GroupAxiom

Axiom has collected data from a compromised network.

T1005
Data from Local System
MalwareHikit

Hikit can upload files from compromised machines.

T1005
Data from Local System
MalwareZox

Zox has the ability to upload files from a targeted system.

T1021.001
Remote Desktop Protocol
GroupAxiom

Axiom has used RDP during operations.

T1021.002
SMB/Windows Admin Shares
MalwareZox

Zox has the ability to use SMB for communication.

T1027.013
Encrypted/Encoded File
MalwareZox

Zox has been encoded with Base64.

T1057
Process Discovery
MalwareZox

Zox has the ability to list processes.

T1068
Exploitation for Privilege Escalation
MalwareZox

Zox has the ability to leverage local and remote exploits to escalate privileges.

T1070.006
Timestomp
MalwareDerusbi

The Derusbi malware supports timestomping.

T1078
Valid Accounts
GroupAxiom

Axiom has used previously compromised administrative accounts to escalate privileges.

T1083
File and Directory Discovery
MalwareZox

Zox can enumerate files on a compromised host.

T1090.001
Internal Proxy
MalwareHikit

Hikit supports peer connections.

T1105
Ingress Tool Transfer
MalwareHikit

Hikit has the ability to download files to a compromised host.

T1105
Ingress Tool Transfer
MalwareZox

Zox can download files to a compromised machine.

T1190
Exploit Public-Facing Application
GroupAxiom

Axiom has been observed using SQL injection to gain access to systems.

T1546.008
Accessibility Features
GroupAxiom

Axiom actors have been known to use the Sticky Keys replacement within RDP sessions to obtain persistence.

T1553
Subvert Trust Controls
GroupAxiom

Axiom has used digital certificates to deliver malware.

T1560
Archive Collected Data
GroupAxiom

Axiom has compressed and encrypted data prior to exfiltration.

T1563.002
RDP Hijacking
GroupAxiom

Axiom has targeted victims with remote administration tools including RDP.

T1566
Phishing
GroupAxiom

Axiom has used spear phishing to initially compromise victims.

T1566
Phishing
MalwareHikit

Hikit has been spread through spear phishing.

T1573.001
Symmetric Cryptography
MalwareHikit

Hikit performs XOR encryption.

T1583.002
DNS Server
GroupAxiom

Axiom has acquired dynamic DNS services for use in the targeting of intended victims.

T1583.003
Virtual Private Server
GroupAxiom

Axiom has used VPS hosting providers in targeting of intended victims.

T1584.005
Botnet
GroupAxiom

Axiom has used large groups of compromised machines for use as proxy nodes.

T1680
Local Storage Discovery
MalwareZox

Zox can enumerate attached drives.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.