ATT&CKReferencesSymantec Chafer February 2018

Symantec Chafer February 2018

Symantec. (2018, February 28). Chafer: Latest Attacks Reveal Heightened Ambitions. Retrieved May 22, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupAPT39

APT39 has used various tools to steal files from the compromised host.

T1018
Remote System Discovery
GroupAPT39

APT39 has used NBTscan and custom tools to discover remote systems.

T1021.002
SMB/Windows Admin Shares
GroupAPT39

APT39 has used SMB for lateral movement.

T1056.001
Keylogging
GroupAPT39

APT39 has used tools for capturing keystrokes.

T1059.001
PowerShell
GroupAPT39

APT39 has used PowerShell to execute malicious code.

T1105
Ingress Tool Transfer
GroupAPT39

APT39 has downloaded tools to compromised hosts.

T1113
Screen Capture
GroupAPT39

APT39 has used a screen capture utility to take screenshots on a compromised host.

T1115
Clipboard Data
GroupAPT39

APT39 has used tools capable of stealing contents of the clipboard.

T1190
Exploit Public-Facing Application
GroupAPT39

APT39 has used SQL injection for initial compromise.

T1204.002
Malicious File
GroupAPT39

APT39 has sent spearphishing emails in an attempt to lure users to click on a malicious attachment.

T1566.001
Spearphishing Attachment
GroupAPT39

APT39 leveraged spearphishing emails with malicious attachments to initially compromise victims.

T1569.002
Service Execution
GroupAPT39

APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.