ATT&CKReferencesMicrosoft Unidentified Dec 2018

Microsoft Unidentified Dec 2018

Microsoft Defender Research Team. (2018, December 3). Analysis of cyberattack on U.S. think tanks, non-profits, public sector by unidentified attackers. Retrieved April 15, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples9

TechniqueUsed byProcedure example
T1027.009
Embedded Payloads
CampaignC0021

For C0021, the threat actors embedded a base64-encoded payload within a LNK file.

T1027.010
Command Obfuscation
CampaignC0021

During C0021, the threat actors used encoded PowerShell commands.

T1059.001
PowerShell
CampaignC0021

During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file.

T1105
Ingress Tool Transfer
CampaignC0021

During C0021, the threat actors downloaded additional tools and files onto victim machines.

T1140
Deobfuscate/Decode Files or Information
CampaignC0021

During C0021, the threat actors deobfuscated encoded PowerShell commands including use of the specific string `'FromBase'+0x40+'String'`, in place of `FromBase64String` which is normally used to decode base64.

T1566.002
Spearphishing Link
CampaignC0021

During C0021, the threat actors sent phishing emails with unique malicious links, likely for tracking victim clicks.

T1584.001
Domains
CampaignC0021

For C0021, the threat actors used legitimate but compromised domains to host malicious payloads.

T1588.002
Tool
CampaignC0021

For C0021, the threat actors used Cobalt Strike configured with a modified variation of the publicly available Pandora Malleable C2 Profile.

T1608.001
Upload Malware
CampaignC0021

For C0021, the threat actors uploaded malware to websites under their control.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.