Novetta. (n.d.). Operation SMN: Axiom Threat Actor Group Report. Retrieved November 12, 2014.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.002 Steganography |
GroupAxiom | Axiom has used steganography to hide its C2 communications. |
| T1001.002 Steganography |
MalwareZox | Zox has used the .PNG file format for C2 communications. |
| T1003 OS Credential Dumping |
GroupAxiom | Axiom has been known to dump credentials. |
| T1005 Data from Local System |
GroupAxiom | Axiom has collected data from a compromised network. |
| T1005 Data from Local System |
MalwareHikit | Hikit can upload files from compromised machines. |
| T1005 Data from Local System |
MalwareZox | Zox has the ability to upload files from a targeted system. |
| T1021.001 Remote Desktop Protocol |
GroupAxiom | Axiom has used RDP during operations. |
| T1021.002 SMB/Windows Admin Shares |
MalwareZox | Zox has the ability to use SMB for communication. |
| T1027.013 Encrypted/Encoded File |
MalwareZox | Zox has been encoded with Base64. |
| T1057 Process Discovery |
MalwareZox | Zox has the ability to list processes. |
| T1068 Exploitation for Privilege Escalation |
MalwareZox | Zox has the ability to leverage local and remote exploits to escalate privileges. |
| T1070.006 Timestomp |
MalwareDerusbi | The Derusbi malware supports timestomping. |
| T1078 Valid Accounts |
GroupAxiom | Axiom has used previously compromised administrative accounts to escalate privileges. |
| T1083 File and Directory Discovery |
MalwareZox | Zox can enumerate files on a compromised host. |
| T1090.001 Internal Proxy |
MalwareHikit | Hikit supports peer connections. |
| T1105 Ingress Tool Transfer |
MalwareHikit | Hikit has the ability to download files to a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareZox | Zox can download files to a compromised machine. |
| T1190 Exploit Public-Facing Application |
GroupAxiom | Axiom has been observed using SQL injection to gain access to systems. |
| T1546.008 Accessibility Features |
GroupAxiom | Axiom actors have been known to use the Sticky Keys replacement within RDP sessions to obtain persistence. |
| T1553 Subvert Trust Controls |
GroupAxiom | Axiom has used digital certificates to deliver malware. |
| T1560 Archive Collected Data |
GroupAxiom | Axiom has compressed and encrypted data prior to exfiltration. |
| T1563.002 RDP Hijacking |
GroupAxiom | Axiom has targeted victims with remote administration tools including RDP. |
| T1566 Phishing |
GroupAxiom | Axiom has used spear phishing to initially compromise victims. |
| T1566 Phishing |
MalwareHikit | Hikit has been spread through spear phishing. |
| T1573.001 Symmetric Cryptography |
MalwareHikit | Hikit performs XOR encryption. |
| T1583.002 DNS Server |
GroupAxiom | Axiom has acquired dynamic DNS services for use in the targeting of intended victims. |
| T1583.003 Virtual Private Server |
GroupAxiom | Axiom has used VPS hosting providers in targeting of intended victims. |
| T1584.005 Botnet |
GroupAxiom | Axiom has used large groups of compromised machines for use as proxy nodes. |
| T1680 Local Storage Discovery |
MalwareZox | Zox can enumerate attached drives. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.