ATT&CKReferencesFireEye Clandestine Fox

FireEye Clandestine Fox

Chen, X., Scott, M., Caselden, D.. (2014, April 26). New Zero-Day Exploit targeting Internet Explorer Versions 9 through 11 Identified in Targeted Attacks. Retrieved January 14, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1018
Remote System Discovery
GroupAPT3

APT3 has a tool that can detect the existence of remote systems.

T1041
Exfiltration Over C2 Channel
GroupAPT3

APT3 has a tool that exfiltrates data over the C2 channel.

T1049
System Network Connections Discovery
GroupAPT3

APT3 has a tool that can enumerate current network connections.

T1057
Process Discovery
GroupAPT3

APT3 has a tool that can list out currently running processes.

T1070.004
File Deletion
GroupAPT3

APT3 has a tool that can delete files.

T1083
File and Directory Discovery
GroupAPT3

APT3 has a tool that looks for files and directories on the local file system.

T1105
Ingress Tool Transfer
GroupAPT3

APT3 has a tool that can copy files to remote machines.

T1203
Exploitation for Client Execution
GroupAPT3

APT3 has exploited the Adobe Flash Player vulnerability CVE-2015-3113 and Internet Explorer vulnerability CVE-2014-1776.

T1218.011
Rundll32
GroupAPT3

APT3 has a tool that can run DLLs.

T1574.001
DLL
GroupAPT3

APT3 has been known to side load DLLs with a valid version of Chrome with one of their tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.