I. Ilascu. (2019, March 3). Op 'Sharpshooter' Connected to North Korea's Lazarus Group. Retrieved September 26, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1090 Proxy |
CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors used the ExpressVPN service to hide their location. |
| T1573.002 Asymmetric Cryptography |
MalwareRising Sun | Rising Sun variants can use SSL for encrypting C2 communications. |
| T1584.004 Server |
CampaignOperation Sharpshooter | For Operation Sharpshooter, the threat actors compromised a server they used as part of the campaign's infrastructure. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.