Lee, B, et al. (2018, February 28). Sofacy Attacks Multiple Government Entities. Retrieved March 15, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
GroupAPT28 | APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4. |
| T1055 Process Injection |
MalwareJHUHUGIT | JHUHUGIT performs code injection injecting its own functions to browser processes. |
| T1057 Process Discovery |
MalwareJHUHUGIT | JHUHUGIT obtains a list of running processes on the victim. |
| T1070.004 File Deletion |
MalwareJHUHUGIT | The JHUHUGIT dropper can delete itself from the victim. Another JHUHUGIT variant has the capability to delete specified files. |
| T1071.001 Web Protocols |
MalwareJHUHUGIT | JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS. |
| T1105 Ingress Tool Transfer |
MalwareJHUHUGIT | JHUHUGIT can retrieve an additional payload from its C2 server. JHUHUGIT has a command to download files to the victim’s machine. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAPT28 | An APT28 macro uses the command |
| T1204.002 Malicious File |
GroupAPT28 | APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts. |
| T1566.001 Spearphishing Attachment |
GroupAPT28 | APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments. |
| T1680 Local Storage Discovery |
MalwareJHUHUGIT | JHUHUGIT obtains a build identifier as well as victim hard drive information from Windows registry key |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.