ATT&CKReferencesevolution of pirpi

evolution of pirpi

Yates, M. (2017, June 18). APT3 Uncovered: The code evolution of Pirpi. Retrieved September 28, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupAPT3

A keylogging tool used by APT3 gathers network information from the victim, including the MAC address, IP address, WINS, DHCP server, and gateway.

T1049
System Network Connections Discovery
GroupAPT3

APT3 has a tool that can enumerate current network connections.

T1057
Process Discovery
GroupAPT3

APT3 has a tool that can list out currently running processes.

T1082
System Information Discovery
GroupAPT3

APT3 has a tool that can obtain information about the local system.

T1083
File and Directory Discovery
GroupAPT3

APT3 has a tool that looks for files and directories on the local file system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.