Mark Graham, Carolyn Ahlers, Kyle O'Meara; Dragos. (2024, July). Impact of FrostyGoop ICS Malware on Connected OT Systems. Retrieved November 20, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
CampaignFrostyGoop Incident | During FrostyGoop Incident, the adversary retrieved the contents of the Security Account Manager (SAM) hive in the victim environment for credential capture. |
| T1071 Application Layer Protocol |
CampaignFrostyGoop Incident | During FrostyGoop Incident, the adversary initiated Layer Two Tunnelling Protocol (L2TP) connections to Moscow-based IP addresses. |
| T1190 Exploit Public-Facing Application |
CampaignFrostyGoop Incident | FrostyGoop Incident was likely enabled by the adversary exploiting an unknown vulnerability in an external-facing router. |
| T1505.003 Web Shell |
CampaignFrostyGoop Incident | FrostyGoop Incident deployed a ReGeorg variant web shell to impacted systems following initial access for persistence. |
| T1689 Downgrade Attack |
CampaignFrostyGoop Incident | During FrostyGoop Incident, the adversary downgraded firmware on victim devices in order to impair visibility into the process environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.