LeeArchinal, 4 months ago Notable MITRE ATT&CK TTPs (thanks to the authors!): TA0001 - Initial Access T1189 - Drive-by Compromise TA0002 - Execution T1204.001 - User Execution: Malicious Link T1059.001 - Command and Scripting Interpreter: PowerShell TA0005 - Defense Evasion T1218.007 - System Binary Proxy Execution: Msiexec T1480 - Execution Guardrails T1070.004 - Indicator Removal: File Deletion T1140 - Deobfuscate/Decode Files or Information TA0011 - Command and Control T1105 - Ingress Tool Transfer T1071.001 - Application Layer Protocol: Web Protocols T1219 - Remote Access Software TA0006 - Credential Access T1056.001 - Input Capture: Keylogging TA0009 - Collection T1056.001 - Input Capture: Keylogging T1113 - Screen Capture TA0010 - Exfiltration T1041 - Exfiltration Over C2 Channel https://blogs.blackberry.com/en/2024/01/mexican-banks-and-cryptocurrency-platforms-targeted-with-allakore-rat #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #gethunting
Notable MITRE ATT&CK TTPs (thanks to the authors!): TA0001 - Initial Access T1189 - Drive-by Compromise
TA0002 - Execution T1204.001 - User Execution: Malicious Link T1059.001 - Command and Scripting Interpreter: PowerShell
TA0005 - Defense Evasion T1218.007 - System Binary Proxy Execution: Msiexec T1480 - Execution Guardrails T1070.004 - Indicator Removal: File Deletion T1140 - Deobfuscate/Decode Files or Information
TA0011 - Command and Control T1105 - Ingress Tool Transfer T1071.001 - Application Layer Protocol: Web Protocols T1219 - Remote Access Software
TA0006 - Credential Access T1056.001 - Input Capture: Keylogging
TA0009 - Collection T1056.001 - Input Capture: Keylogging T1113 - Screen Capture
TA0010 - Exfiltration T1041 - Exfiltration Over C2 Channel
https://blogs.blackberry.com/en/2024/01/mexican-banks-and-cryptocurrency-platforms-targeted-with-allakore-rat
#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #gethunting