Adair, S. and Lancaster, T. (2020, November 6). OceanLotus: Extending Cyber Espionage Operations Through Fake Websites. Retrieved November 20, 2020.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT32 | APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe. |
| T1059.007 JavaScript |
GroupAPT32 | APT32 has used JavaScript for drive-by downloads and C2 communications. |
| T1102 Web Service |
GroupAPT32 | APT32 has used Dropbox, Amazon S3, and Google Drive to host malicious downloads. |
| T1189 Drive-by Compromise |
GroupAPT32 | APT32 has infected victims by tricking them into visiting compromised watering hole websites. |
| T1204.001 Malicious Link |
GroupAPT32 | APT32 has lured targets to download a Cobalt Strike beacon by including a malicious link within spearphishing emails. |
| T1566.002 Spearphishing Link |
GroupAPT32 | APT32 has sent spearphishing emails containing malicious links. |
| T1583.001 Domains |
GroupAPT32 | APT32 has set up and operated websites to gather information and deliver malware. |
| T1583.006 Web Services |
GroupAPT32 | APT32 has set up Dropbox, Amazon S3, and Google Drive to host malicious downloads. |
| T1585.001 Social Media Accounts |
GroupAPT32 | APT32 has set up Facebook pages in tandem with fake websites. |
| T1598.003 Spearphishing Link |
GroupAPT32 | APT32 has used malicious links to direct users to web pages designed to harvest credentials. |
| T1608.001 Upload Malware |
GroupAPT32 | APT32 has hosted malicious payloads in Dropbox, Amazon S3, and Google Drive for use during targeting. |
| T1608.004 Drive-by Target |
GroupAPT32 | APT32 has stood up websites containing numerous articles and content scraped from the Internet to make them appear legitimate, but some of these pages include malicious JavaScript to profile the potential victim or infect them via a fake software update. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.