Group overview
Not a Ransomware Group
Preferred targets
Public Sector · 2
Energy · 1
Most targeted countries
US · 1
Tactics & techniques (MITRE ATT&CK)
Initial Access
Valid Accounts
Valid Accounts: Domain Accounts
Valid Accounts: Cloud Accounts
External Remote Services
Exploit Public-Facing Application
Trusted Relationship
Phishing
Execution
Windows Management Instrumentation
Command and Scripting Interpreter: PowerShell
Command and Scripting Interpreter: Python
Software Deployment Tools
User Execution: Malicious File
Cloud Administration Command
Persistence
Valid Accounts
Valid Accounts: Domain Accounts
Valid Accounts: Cloud Accounts
Account Manipulation
External Remote Services
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Privilege Escalation
Valid Accounts
Valid Accounts: Domain Accounts
Valid Accounts: Cloud Accounts
Account Manipulation
Domain or Tenant Policy Modification: Group Policy Modification
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Stealth
Obfuscated Files or Information: Compression
Masquerading: Masquerade Task or Service
Masquerading: Match Legitimate Resource Name or Location
Valid Accounts
Valid Accounts: Domain Accounts
Valid Accounts: Cloud Accounts
Hide Artifacts: Hidden Window
Selective Exclusion
Credential Access
OS Credential Dumping: LSASS Memory
Brute Force
Brute Force: Password Guessing
Brute Force: Credential Stuffing
Unsecured Credentials: Credentials in Registry
Discovery
System Information Discovery
Account Discovery: Domain Account
Lateral Movement
Remote Services: Remote Desktop Protocol
Software Deployment Tools