Mercer, W., et al. (2017, October 22). "Cyber Conflict" Decoy Document Used in Real Cyber Conflict. Retrieved November 2, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
GroupAPT28 | APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4. |
| T1027.013 Encrypted/Encoded File |
MalwareJHUHUGIT | Many strings in JHUHUGIT are obfuscated with a XOR algorithm. |
| T1037.001 Logon Script (Windows) |
MalwareJHUHUGIT | JHUHUGIT has registered a Windows shell script under the Registry key |
| T1059.003 Windows Command Shell |
MalwareJHUHUGIT | JHUHUGIT uses a .bat file to execute a .dll. |
| T1059.003 Windows Command Shell |
GroupAPT28 | An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads. |
| T1105 Ingress Tool Transfer |
MalwareJHUHUGIT | JHUHUGIT can retrieve an additional payload from its C2 server. JHUHUGIT has a command to download files to the victim’s machine. |
| T1113 Screen Capture |
MalwareJHUHUGIT | A JHUHUGIT variant takes screenshots by simulating the user pressing the "Take Screenshot" key (VK_SCREENSHOT), accessing the screenshot saved in the clipboard, and converting it to a JPG image. |
| T1218.011 Rundll32 |
MalwareJHUHUGIT | JHUHUGIT is executed using rundll32.exe. |
| T1546.015 Component Object Model Hijacking |
MalwareJHUHUGIT | JHUHUGIT has used COM hijacking to establish persistence by hijacking a class named MMDeviceEnumerator and also by registering the payload as a Shell Icon Overlay handler COM object ({3543619C-D563-43f7-95EA-4DA7E1CC396A}). |
| T1564.001 Hidden Files and Directories |
GroupAPT28 | APT28 has saved files with hidden file attributes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.