Dunwoody, M. and Carr, N.. (2016, September 27). No Easy Breach DerbyCon 2016. Retrieved September 12, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
GroupAPT29 | APT29 used UPX to pack files. |
| T1047 Windows Management Instrumentation |
GroupAPT29 | APT29 used WMI to steal credentials and execute backdoors at a future time. |
| T1053.005 Scheduled Task |
GroupAPT29 | APT29 has used named and hijacked scheduled tasks to establish persistence. |
| T1059.001 PowerShell |
GroupAPT29 | APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke. |
| T1070.004 File Deletion |
GroupAPT29 | APT29 has used SDelete to remove artifacts from victim networks. |
| T1090.003 Multi-hop Proxy |
GroupAPT29 | A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network and has also used TOR. |
| T1090.004 Domain Fronting |
GroupAPT29 | APT29 has used the meek domain fronting plugin for Tor to hide the destination of C2 traffic. |
| T1105 Ingress Tool Transfer |
GroupAPT29 | APT29 has downloaded additional tools and malware onto compromised networks. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupAPT29 | APT29 has used WMI event subscriptions for persistence. |
| T1546.008 Accessibility Features |
GroupAPT29 | APT29 used sticky-keys to obtain unauthenticated, privileged console access. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT29 | APT29 added Registry Run keys to establish persistence. |
| T1548.002 Bypass User Account Control |
GroupAPT29 | APT29 has bypassed UAC. |
| T1550.003 Pass the Ticket |
GroupAPT29 | APT29 used Kerberos ticket attacks for lateral movement. |
| T1560.002 Archive via Library |
MalwareSeaDuke | SeaDuke compressed data with zlib prior to sending it over C2. |
| T1566.002 Spearphishing Link |
GroupAPT29 | APT29 has used spearphishing with a link to trick victims into clicking on a link to a zip file containing malicious files. |
| T1573.001 Symmetric Cryptography |
MalwareSeaDuke | SeaDuke C2 traffic has been encrypted with RC4 and AES. |
| T1587.001 Malware |
GroupAPT29 | APT29 has used unique malware in many of their operations. |
| T1588.002 Tool |
GroupAPT29 | APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.