ATT&CKReferencesCisco Group 72

Cisco Group 72

Esler, J., Lee, M., and Williams, C. (2014, October 14). Threat Spotlight: Group 72. Retrieved January 14, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1189
Drive-by Compromise
GroupAxiom

Axiom has used watering hole attacks to gain access.

T1190
Exploit Public-Facing Application
GroupAxiom

Axiom has been observed using SQL injection to gain access to systems.

T1203
Exploitation for Client Execution
GroupAxiom

Axiom has used exploits for multiple vulnerabilities including CVE-2014-0322, CVE-2012-4792, CVE-2012-1889, and CVE-2013-3893.

T1566
Phishing
GroupAxiom

Axiom has used spear phishing to initially compromise victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.