OutSteel
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols |
OutSteel has used HTTP for C2 communications.(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 ) |
Enterprise | T1059 | .003 | Command and Scripting Interpreter: Windows Command Shell |
OutSteel has used `cmd.exe` to scan a compromised host for specific file extensions.(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 ) |
.010 | Command and Scripting Interpreter: AutoHotKey & AutoIT |
OutSteel was developed using the AutoIT scripting language.(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 ) |
||
Enterprise | T1070 | .004 | Indicator Removal: File Deletion |
OutSteel can delete itself following the successful execution of a follow-on payload.(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 ) |
Enterprise | T1036 | .005 | Masquerading: Match Legitimate Name or Location |
OutSteel attempts to download and execute Saint Bot to a statically-defined location attempting to mimic svchost: |
Enterprise | T1566 | .001 | Phishing: Spearphishing Attachment |
OutSteel has been distributed as a malicious attachment within a spearphishing email.(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 ) |
.002 | Phishing: Spearphishing Link |
OutSteel has been distributed through malicious links contained within spearphishing emails.(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 ) |
||
Enterprise | T1204 | .001 | User Execution: Malicious Link |
OutSteel has relied on a user to click a malicious link within a spearphishing email.(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 ) |
.002 | User Execution: Malicious File |
OutSteel has relied on a user to execute a malicious attachment delivered via spearphishing.(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 ) |
Groups That Use This Software |
||
ID | Name | References |
---|---|---|
G1031 | Saint Bear |
(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 ) |
G1003 | Ember Bear |
(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 ) |
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.