Threat Actor ๐ท๐บ Russia
Inception Framework
Also known as: Clean Ursa ยท Cloud Atlas ยท OXYGEN ยท G0100 ยท ATK116 ยท Blue Odin
This threat actor uses spear-phishing techniques to target private-sector energy, defense, aerospace, research, and media organizations and embassies in Africa, Europe, and the Middle East, for the purpose of espionage.
Indicators of Compromise 3
MITRE ATT&CK TTPs 13
T1003.002 T1021.002 T1055 T1059.001 T1071.001 T1078 T1085 T1133 T1204.002 T1212 T1485 T1558 T1566
Security Account Manager
Credential Access
SMB/Windows Admin Shares
Lateral Movement
Process Injection
Defense Evasion
PowerShell
Execution
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
T1085
External Remote Services
Persistence
Malicious File
Execution
Exploitation for Credential Access
Credential Access
Data Destruction
Impact
Steal or Forge Kerberos Tickets
Credential Access
Phishing
Initial Access