Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAPT1 | APT1 has been known to use credential dumping using Mimikatz. |
| T1003.001 LSASS Memory |
ToolLslsass | Lslsass can dump active logon session password hashes from the lsass process. |
| T1003.002 Security Account Manager |
ToolFgdump | Fgdump can dump Windows password hashes. |
| T1003.005 Cached Domain Credentials |
ToolCachedump | Cachedump can extract cached password hashes from cache entry information. |
| T1005 Data from Local System |
GroupAPT1 | APT1 has collected files from a local victim. |
| T1007 System Service Discovery |
GroupAPT1 | APT1 used the commands |
| T1008 Fallback Channels |
MalwareBISCUIT | BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server. |
| T1016 System Network Configuration Discovery |
GroupAPT1 | APT1 used the |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT1 | The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware. |
| T1049 System Network Connections Discovery |
GroupAPT1 | APT1 used the |
| T1057 Process Discovery |
GroupAPT1 | APT1 gathered a list of running processes on the system using |
| T1059.003 Windows Command Shell |
MalwareWEBC2 | WEBC2 can open an interactive command shell. |
| T1059.003 Windows Command Shell |
GroupAPT1 | APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. |
| T1082 System Information Discovery |
MalwareBISCUIT | BISCUIT has a command to collect the processor type, operation system, computer name, and whether the system is a laptop or PC. |
| T1087.001 Local Account |
GroupAPT1 | APT1 used the commands |
| T1102.002 Bidirectional Communication |
MalwareGLOOXMAIL | GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol. |
| T1102.002 Bidirectional Communication |
MalwareCALENDAR | The CALENDAR malware communicates through the use of events in Google Calendar. |
| T1105 Ingress Tool Transfer |
MalwareWEBC2 | WEBC2 can download and execute a file. |
| T1114.001 Local Email Collection |
GroupAPT1 | APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. GETMAIL extracts emails from archived Outlook .pst files. |
| T1114.002 Remote Email Collection |
GroupAPT1 | APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived. |
| T1119 Automated Collection |
GroupAPT1 | APT1 used a batch script to perform a series of discovery techniques and saves it to a text file. |
| T1124 System Time Discovery |
MalwareBISCUIT | BISCUIT has a command to collect the system `UPTIME`. |
| T1135 Network Share Discovery |
GroupAPT1 | APT1 listed connected network shares. |
| T1550.002 Pass the Hash |
GroupAPT1 | The APT1 group is known to have used pass the hash. |
| T1550.002 Pass the Hash |
ToolPass-The-Hash Toolkit | Pass-The-Hash Toolkit can perform pass the hash. |
| T1560.001 Archive via Utility |
GroupAPT1 | APT1 has used RAR to compress files before moving them outside of the victim network. |
| T1566.001 Spearphishing Attachment |
GroupAPT1 | APT1 has sent spearphishing emails containing malicious attachments. |
| T1566.002 Spearphishing Link |
GroupAPT1 | APT1 has sent spearphishing emails containing hyperlinks to malicious files. |
| T1583.001 Domains |
GroupAPT1 | APT1 has registered hundreds of domains for use in operations. |
| T1584.001 Domains |
GroupAPT1 | APT1 hijacked FQDNs associated with legitimate websites hosted by hop points. |
| T1585.002 Email Accounts |
GroupAPT1 | APT1 has created email accounts for later use in social engineering, phishing, and when registering domains. |
| T1588.001 Malware |
GroupAPT1 | APT1 used publicly available malware for privilege escalation. |
| T1588.002 Tool |
GroupAPT1 | APT1 has used various open-source tools for privilege escalation purposes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.