Arsene, L. (2020, April 21). Oil & Gas Spearphishing Campaigns Drop Agent Tesla Spyware in Advance of Historic OPEC+ Deal. Retrieved May 19, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareAgent Tesla | Agent Tesla has used wmi queries to gather information from the system. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareAgent Tesla | Agent Tesla has routines for exfiltration over SMTP, FTP, and HTTP. |
| T1056.001 Keylogging |
MalwareAgent Tesla | Agent Tesla can log keystrokes on the victim’s machine. |
| T1071.003 Mail Protocols |
MalwareAgent Tesla | Agent Tesla has used SMTP for C2 communications. |
| T1113 Screen Capture |
MalwareAgent Tesla | Agent Tesla can capture screenshots of the victim’s desktop. |
| T1115 Clipboard Data |
MalwareAgent Tesla | Agent Tesla can steal data from the victim’s clipboard. |
| T1185 Browser Session Hijacking |
MalwareAgent Tesla | Agent Tesla has the ability to use form-grabbing to extract data from web data forms. |
| T1204.002 Malicious File |
MalwareAgent Tesla | Agent Tesla has been executed through malicious e-mail attachments |
| T1555.003 Credentials from Web Browsers |
MalwareAgent Tesla | Agent Tesla can gather credentials from a number of browsers. |
| T1566.001 Spearphishing Attachment |
MalwareAgent Tesla | The primary delivered mechanism for Agent Tesla is through email phishing messages. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.