Threat Actor Unknown origin
TetrisPhantom
TetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by government organizations. While investigating this threat, experts identified an entire spying campaign that uses a range of malicious modules to execute commands, collect files and information from compromised computers and transfer them to other machines also using secure USB drives.
MITRE ATT&CK TTPs 15
T1021.003 T1059.001 T1071.001 T1082 T1083 T1098 T1105 T1110 T1114 T1129 T1133 T1140 T1566 T1573 T1574
Distributed Component Object Model
Lateral Movement
PowerShell
Execution
Web Protocols
Command And Control
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Account Manipulation
Persistence
Ingress Tool Transfer
Command And Control
Brute Force
Credential Access
Email Collection
Collection
Shared Modules
Execution
External Remote Services
Persistence
Deobfuscate/Decode Files or Information
Defense Evasion
Phishing
Initial Access
Encrypted Channel
Command And Control
Hijack Execution Flow
Persistence