Chen, X., Scott, M., Caselden, D.. (2014, April 26). New Zero-Day Exploit targeting Internet Explorer Versions 9 through 11 Identified in Targeted Attacks. Retrieved January 14, 2016.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
GroupAPT3 | APT3 has a tool that can detect the existence of remote systems. |
| T1041 Exfiltration Over C2 Channel |
GroupAPT3 | APT3 has a tool that exfiltrates data over the C2 channel. |
| T1049 System Network Connections Discovery |
GroupAPT3 | APT3 has a tool that can enumerate current network connections. |
| T1057 Process Discovery |
GroupAPT3 | APT3 has a tool that can list out currently running processes. |
| T1070.004 File Deletion |
GroupAPT3 | APT3 has a tool that can delete files. |
| T1083 File and Directory Discovery |
GroupAPT3 | APT3 has a tool that looks for files and directories on the local file system. |
| T1105 Ingress Tool Transfer |
GroupAPT3 | APT3 has a tool that can copy files to remote machines. |
| T1203 Exploitation for Client Execution |
GroupAPT3 | APT3 has exploited the Adobe Flash Player vulnerability CVE-2015-3113 and Internet Explorer vulnerability CVE-2014-1776. |
| T1218.011 Rundll32 |
GroupAPT3 | APT3 has a tool that can run DLLs. |
| T1574.001 DLL |
GroupAPT3 | APT3 has been known to side load DLLs with a valid version of Chrome with one of their tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.