Huntley, S. (2020, October 16). How We're Tackling Evolving Online Threats. Retrieved March 24, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036 Masquerading |
GroupZIRCONIUM | ZIRCONIUM has spoofed legitimate applications in phishing lures and changed file extensions to conceal installation of malware. |
| T1059.006 Python |
GroupZIRCONIUM | ZIRCONIUM has used Python-based implants to interact with compromised hosts. |
| T1102.002 Bidirectional Communication |
GroupZIRCONIUM | ZIRCONIUM has used Dropbox for C2 allowing upload and download of files as well as execution of arbitrary commands. |
| T1204.001 Malicious Link |
GroupZIRCONIUM | ZIRCONIUM has used malicious links in e-mails to lure victims into downloading malware. |
| T1566.002 Spearphishing Link |
GroupZIRCONIUM | ZIRCONIUM has used malicious links in e-mails to deliver malware. |
| T1583.006 Web Services |
GroupZIRCONIUM | ZIRCONIUM has used GitHub to host malware linked in spearphishing e-mails. |
| T1598 Phishing for Information |
GroupZIRCONIUM | ZIRCONIUM targeted presidential campaign staffers with credential phishing e-mails. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.