Alternative names (2)
TTPsInclude • usedTTPsRandom triples
| Subject | Object |
|---|---|
| gptkb:APT12 | spear phishing |
| gptkb:APT20 | data exfiltration |
| gptkb:Conti_ransomware_campaigns | PowerShell scripts |
| gptkb:APT41 | privilege escalation |
| gptkb:APT12 | custom malware deployment |
| gptkb:APT60 | custom malware |
| gptkb:APT41 | supply chain compromise |
| gptkb:Conti_ransomware_campaigns | malicious attachments |
| gptkb:Winnti | credential theft |
| gptkb:Winnti | watering hole attacks |
| gptkb:Zebrocy | initial access via phishing |
| gptkb:APT41 | credential theft |
| gptkb:Conti_ransomware_campaigns | disabling security software |
| gptkb:APT41 | use of compromised credentials |
| gptkb:MuddyWater_group | use of compromised email accounts |
| gptkb:APT54 | use of PowerShell scripts |
| gptkb:Stone_Panda | use of legitimate credentials |
| gptkb:APT54 | use of legitimate credentials |
| gptkb:APT60 | spear phishing |
| gptkb:Conti_ransomware_campaigns | remote access tools |