Secureworks CTU. (n.d.). IRON HEMLOCK. Retrieved February 22, 2022.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
GroupAPT29 | APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke. |
| T1204.002 Malicious File |
GroupAPT29 | APT29 has used various forms of spearphishing attempting to get a user to open attachments, including, but not limited to, malicious Microsoft Word documents, .pdf, and .lnk files. |
| T1566.001 Spearphishing Attachment |
GroupAPT29 | APT29 has used spearphishing emails with an attachment to deliver files with exploits to initial victims. |
| T1573 Encrypted Channel |
GroupAPT29 | APT29 has used multiple layers of encryption within malware to protect C2 communication. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.