Mueller, R. (2018, July 13). Indictment - United States of America vs. VIKTOR BORISOVICH NETYKSHO, et al. Retrieved November 17, 2024.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. |
| T1003.001 LSASS Memory |
GroupAPT28 | APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function. |
| T1005 Data from Local System |
GroupAPT28 | APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration. |
| T1056.001 Keylogging |
MalwareCHOPSTICK | CHOPSTICK is capable of performing keylogging. |
| T1056.001 Keylogging |
GroupAPT28 | APT28 has used tools to perform keylogging. |
| T1070.004 File Deletion |
GroupAPT28 | APT28 has intentionally deleted computer files to cover their tracks, including with use of the program CCleaner. |
| T1078 Valid Accounts |
GroupAPT28 | APT28 has used legitimate credentials to gain initial access, maintain access, and exfiltrate data from a victim network. The group has specifically used credentials stolen through a spearphishing email to login to the DCCC network. The group has also leveraged default manufacturer's passwords to gain initial access to corporate networks via IoT devices such as a VOIP phone, printer, and video decoder. |
| T1083 File and Directory Discovery |
GroupAPT28 | APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection. The group also searched a compromised DCCC computer for specific terms. |
| T1090.002 External Proxy |
GroupAPT28 | APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server. |
| T1113 Screen Capture |
MalwareCHOPSTICK | CHOPSTICK has the capability to capture screenshots. |
| T1113 Screen Capture |
GroupAPT28 | APT28 has used tools to take screenshots from victims. |
| T1114.002 Remote Email Collection |
GroupAPT28 | APT28 has collected emails from victim Microsoft Exchange servers. |
| T1119 Automated Collection |
GroupAPT28 | APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks. |
| T1199 Trusted Relationship |
GroupAPT28 | Once APT28 gained access to the DCCC network, the group then proceeded to use that access to compromise the DNC network. |
| T1560 Archive Collected Data |
GroupAPT28 | APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks. |
| T1566.001 Spearphishing Attachment |
GroupAPT28 | APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments. |
| T1598.003 Spearphishing Link |
GroupAPT28 | APT28 has conducted credential phishing campaigns with links that redirect to credential harvesting sites. |
| T1685.005 Clear Windows Event Logs |
GroupAPT28 | APT28 has cleared event logs, including by using the commands |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.