ATT&CKReferencesBleeping Computer Op Sharpshooter March 2019

Bleeping Computer Op Sharpshooter March 2019

I. Ilascu. (2019, March 3). Op 'Sharpshooter' Connected to North Korea's Lazarus Group. Retrieved September 26, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples3

TechniqueUsed byProcedure example
T1090
Proxy
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors used the ExpressVPN service to hide their location.

T1573.002
Asymmetric Cryptography
MalwareRising Sun

Rising Sun variants can use SSL for encrypting C2 communications.

T1584.004
Server
CampaignOperation Sharpshooter

For Operation Sharpshooter, the threat actors compromised a server they used as part of the campaign's infrastructure.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.