🇰🇵

Opal Sleet

APT Group 5 zero-day CVEs ETDA ✓

Details

Origin 🇰🇵 KP
Last Updated 03 Feb 2024

MITRE ATT&CK 64

T1003 - OS Credential Dumping T1005 - Data from Local System T1010 T1012 - Query Registry T1018 - Remote System Discovery T1021.001 - Remote Desktop Protocol T1027 - Obfuscated Files or Information T1033 T1036 - Masquerading T1040 T1041 - Exfiltration Over C2 Channel T1049 - System Network Connections Discovery T1053 - Scheduled Task/Job T1053.005 - Scheduled Task T1055 - Process Injection T1056 - Input Capture T1059 - Command and Scripting Interpreter T1059.001 - PowerShell T1059.003 - Windows Command Shell T1059.005 - Visual Basic T1068 - Exploitation for Privilege Escalation T1070 - Indicator Removal on Host T1070.001 - Clear Windows Event Logs T1070.004 - File Deletion T1071 - Application Layer Protocol T1071.001 - Web Protocols T1078 - Valid Accounts T1082 - System Information Discovery T1102 - Web Service T1105 - Ingress Tool Transfer T1106 - Native API T1112 - Modify Registry T1113 - Screen Capture T1123 - Audio Capture T1125 - Video Capture T1132.001 - Standard Encoding T1140 - Deobfuscate/Decode Files or Information T1176 - Browser Extensions T1190 - Exploit Public-Facing Application T1204 - User Execution T1204.001 - Malicious Link T1204.002 - Malicious File T1218 - Signed Binary Proxy Execution T1218.011 - Rundll32 T1485 - Data Destruction T1490 - Inhibit System Recovery T1498 - Network Denial of Service T1518 - Software Discovery T1531 - Account Access Removal T1539 - Steal Web Session Cookie T1546 - Event Triggered Execution T1547 - Boot or Logon Autostart Execution T1547.001 - Registry Run Keys / Startup Folder T1553 - Subvert Trust Controls T1555.003 - Credentials from Web Browsers T1562 - Impair Defenses T1564 - Hide Artifacts T1566 - Phishing T1566.001 - Spearphishing Attachment T1573 - Encrypted Channel T1583 - Acquire Infrastructure T1584 - Compromise Infrastructure T1588.001 - Malware T1588.002 - Tool