ATT&CKReferencesESET T3 Threat Report 2021

ESET T3 Threat Report 2021

ESET. (2022, February). THREAT REPORT T3 2021. Retrieved February 10, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1027.006
HTML Smuggling
GroupAPT29

APT29 has embedded an ISO file within an HTML attachment that contained JavaScript code to initiate malware execution.

T1059.001
PowerShell
GroupAPT29

APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke.

T1068
Exploitation for Privilege Escalation
GroupAPT29

APT29 has exploited CVE-2021-36934 to escalate privileges on a compromised host.

T1204.002
Malicious File
GroupAPT29

APT29 has used various forms of spearphishing attempting to get a user to open attachments, including, but not limited to, malicious Microsoft Word documents, .pdf, and .lnk files.

T1218.005
Mshta
GroupAPT29

APT29 has use `mshta` to execute malicious scripts on a compromised host.

T1553.005
Mark-of-the-Web Bypass
GroupAPT29

APT29 has embedded ISO images and VHDX files in HTML to evade Mark-of-the-Web.

T1566.001
Spearphishing Attachment
GroupAPT29

APT29 has used spearphishing emails with an attachment to deliver files with exploits to initial victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.