ATT&CKReferencesGoogle Iran Threats October 2021

Google Iran Threats October 2021

Bash, A. (2021, October 14). Countering threats from Iran. Retrieved January 4, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1567
Exfiltration Over Web Service
GroupMagic Hound

Magic Hound has used the Telegram API `sendMessage` to relay data on compromised devices.

T1584.001
Domains
GroupMagic Hound

Magic Hound has used compromised domains to host links targeted to specific phishing victims.

T1589.002
Email Addresses
GroupMagic Hound

Magic Hound has identified high-value email accounts in academia, journalism, NGO's, foreign policy, and national security for targeting.

T1590.005
IP Addresses
GroupMagic Hound

Magic Hound has captured the IP addresses of visitors to their phishing sites.

T1591.001
Determine Physical Locations
GroupMagic Hound

Magic Hound has collected location information from visitors to their phishing sites.

T1592.002
Software
GroupMagic Hound

Magic Hound has captured the user-agent strings from visitors to their phishing sites.

T1598.003
Spearphishing Link
GroupMagic Hound

Magic Hound has used SMS and email messages with links designed to steal credentials or track victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.